• DocumentCode
    1597843
  • Title

    An Android Application Sandbox system for suspicious software detection

  • Author

    Bläsing, Thomas ; Batyuk, Leonid ; Schmidt, Aubrey-Derrick ; Camtepe, Seyit Ahmet ; Albayrak, Sahin

  • Author_Institution
    DAI-Labor, Tech. Univ. Berlin, Berlin, Germany
  • fYear
    2010
  • Firstpage
    55
  • Lastpage
    62
  • Abstract
    Smartphones are steadily gaining popularity, creating new application areas as their capabilities increase in terms of computational power, sensors and communication. Emerging new features of mobile devices give opportunity to new threats. Android is one of the newer operating systems targeting smartphones. While being based on a Linux kernel, Android has unique properties and specific limitations due to its mobile nature. This makes it harder to detect and react upon malware attacks if using conventional techniques. In this paper, we propose an Android Application Sandbox (AASandbox) which is able to perform both static and dynamic analysis on Android programs to automatically detect suspicious applications. Static analysis scans the software for malicious patterns without installing it. Dynamic analysis executes the application in a fully isolated environment, i.e. sandbox, which intervenes and logs low-level interactions with the system for further analysis. Both the sandbox and the detection algorithms can be deployed in the cloud, providing a fast and distributed detection of suspicious software in a mobile software store akin to Google´s Android Market. Additionally, AASandbox might be used to improve the efficiency of classical anti-virus applications available for the Android operating system.
  • Keywords
    cloud computing; invasive software; mobile computing; mobile handsets; operating system kernels; program diagnostics; system monitoring; Android application sandbox system; Android operating system; Android programs analysis; Googles Android market; Linux kernel; antivirus application; malware attack; mobile device; mobile software store; smartphones; suspicious software detection; Kernel; Malware; Mobile communication; Smart phones;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Malicious and Unwanted Software (MALWARE), 2010 5th International Conference on
  • Conference_Location
    Nancy, Lorraine
  • Print_ISBN
    978-1-4244-9353-1
  • Type

    conf

  • DOI
    10.1109/MALWARE.2010.5665792
  • Filename
    5665792