• DocumentCode
    2989831
  • Title

    Kernel-based Behavior Analysis for Android Malware Detection

  • Author

    Isohara, Takamasa ; Takemori, Keisuke ; Kubota, Ayumu

  • Author_Institution
    KDDI R&D Labs.. Saitama, Saitama, Japan
  • fYear
    2011
  • fDate
    3-4 Dec. 2011
  • Firstpage
    1011
  • Lastpage
    1015
  • Abstract
    The most major threat of Android users is malware infection via Android application markets. In case of the Android Market, as security inspections are not applied for many users have uploaded applications. Therefore, malwares, e.g., Geimini and Droid Dream will attempt to leak personal information, getting root privilege, and abuse functions of the smart phone. An audit framework called log cat is implemented on the Dalvik virtual machine to monitor the application behavior. However, only the limited events are dumped, because an application developers use the log cat for debugging. The behavior monitoring framework that can audit all activities of applications is important for security inspections on the market places. In this paper, we propose a kernel-base behavior analysis for android malware inspection. The system consists of a log collector in the Linux layer and a log analysis application. The log collector records all system calls and filters events with the target application. The log analyzer matches activities with signatures described by regular expressions to detect a malicious activity. Here, signatures of information leakage are automatically generated using the smart phone IDs, e.g., phone number, SIM serial number, and Gmail accounts. We implement a prototype system and evaluate 230 applications in total. The result shows that our system can effectively detect malicious behaviors of the unknown applications.
  • Keywords
    Linux; invasive software; mobile computing; operating system kernels; program debugging; smart phones; system monitoring; systems analysis; virtual machines; Android malware detection; Dalvik virtual machine; Droid Dream malware; Geimini malware; Linux layer; application behavior monitoring; audit framework; behavior monitoring framework; debugging; event filtering; information leakage signature; kernel-base behavior analysis; kernel-based behavior analysis; log analysis application; log cat; log collector; malicious activity detection; malicious behavior detection; malware infection; personal information leakage; security inspection; smart phone; Androids; Humanoid robots; Malware; Mobile communication; Operating systems; Smart phones; Android; malware; smartphone security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Security (CIS), 2011 Seventh International Conference on
  • Conference_Location
    Hainan
  • Print_ISBN
    978-1-4577-2008-6
  • Type

    conf

  • DOI
    10.1109/CIS.2011.226
  • Filename
    6128277