Back to Search
Start Over
DroidChain: A novel Android malware detection method based on behavior chains
- Source :
- Pervasive and Mobile Computing. 32:3-14
- Publication Year :
- 2016
- Publisher :
- Elsevier BV, 2016.
-
Abstract
- The drastic increase of Android malware has led to strong interest in automating malware analysis. In this paper, to fight against malware variants and zero-day malware, we proposed DroidChain: a method combining static analysis and a behavior chain model. We transform the malware detection problem into more accessible matrix form. Using this method, we propose four kinds of malware models, including privacy leakage, SMS financial charges, malware installation, and privilege escalation. To reduce time complexity, we propose the WxShall-extend algorithm. We had moved the prototype to GitHub and evaluate using 1260 malware samples. Experimental malware detection results demonstrate accuracy, precision, and recall of 73%–93%, 71%–99%, and 42%–92%, respectively. Calculation time accounts for 6.58% of the well-known Warshall algorithm’s expense. Results demonstrate that our method, which can detect four kinds of malware simultaneously, is better than Androguard and Kirin.
- Subjects :
- Software_OPERATINGSYSTEMS
Cyber-collection
Computer Networks and Communications
Computer science
020206 networking & telecommunications
02 engineering and technology
Static analysis
computer.software_genre
Computer security
Computer Science Applications
Cryptovirology
ComputingMilieux_MANAGEMENTOFCOMPUTINGANDINFORMATIONSYSTEMS
Hardware and Architecture
0202 electrical engineering, electronic engineering, information engineering
Malware
020201 artificial intelligence & image processing
Data mining
Malware analysis
computer
Asprox botnet
Time complexity
Privilege escalation
Software
Information Systems
Subjects
Details
- ISSN :
- 15741192
- Volume :
- 32
- Database :
- OpenAIRE
- Journal :
- Pervasive and Mobile Computing
- Accession number :
- edsair.doi...........be9ee7e45cf08f2bd83cd9c0c0dc115d
- Full Text :
- https://doi.org/10.1016/j.pmcj.2016.06.018