• DocumentCode
    2258974
  • Title

    Automated Static Code Analysis for Classifying Android Applications Using Machine Learning

  • Author

    Shabtai, Asaf ; Fledel, Yuval ; Elovici, Yuval

  • Author_Institution
    Dept. of Inf. Syst. Eng., Ben-Gurion Univ. of the Negev, Beer-Sheva, Israel
  • fYear
    2010
  • fDate
    11-14 Dec. 2010
  • Firstpage
    329
  • Lastpage
    333
  • Abstract
    In this paper we apply Machine Learning (ML) techniques on static features that are extracted from Android´s application files for the classification of the files. Features are extracted from Android´s Java byte-code (i.e.,.dex files) and other file types such as XML-files. Our evaluation focused on classifying two types of Android applications: tools and games. Successful differentiation between games and tools is expected to provide positive indication about the ability of such methods to learn and model Android benign applications and potentially detect malware files. The results of an evaluation, performed using a test collection comprising 2,285 Android .apk files, indicate that features, extracted statically from .apk files, coupled with ML classification algorithms can provide good indication about the nature of an Android application without running the application, and may assist in detecting malicious applications. This method can be used for rapid examination of Android .apks and informing of suspicious applications.
  • Keywords
    Java; XML; file organisation; invasive software; learning (artificial intelligence); mobile computing; mobile handsets; operating systems (computers); pattern classification; program diagnostics; Android application; Java byte-code; ML classification algorithm; XML file; automated static code analysis; file classification; machine learning; malicious application detection; malware file; operating system; smart phone; static feature extraction; Android; Machine Learning; Malware; Mobile Devices; Security; Static analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Security (CIS), 2010 International Conference on
  • Conference_Location
    Nanning
  • Print_ISBN
    978-1-4244-9114-8
  • Electronic_ISBN
    978-0-7695-4297-3
  • Type

    conf

  • DOI
    10.1109/CIS.2010.77
  • Filename
    5696292