• DocumentCode
    3672872
  • Title

    Effectiveness of Opcode ngrams for Detection of Multi Family Android Malware

  • Author

    Gerardo Canfora;Andrea De Lorenzo;Eric Medvet;Francesco Mercaldo;Corrado Aaron Visaggio

  • Author_Institution
    Dept. of Eng., Univ. of Sannio, Benevento, Italy
  • fYear
    2015
  • Firstpage
    333
  • Lastpage
    340
  • Abstract
    With the wide diffusion of smartphones and their usage in a plethora of processes and activities, these devices have been handling an increasing variety of sensitive resources. Attackers are hence producing a large number of malware applications for Android (the most spread mobile platform), often by slightly modifying existing applications, which results in malware being organized in families. Some works in the literature showed that opcodes are informative for detecting malware, not only in the Android platform. In this paper, we investigate if frequencies of ngrams of opcodes are effective in detecting Android malware and if there is some significant malware family for which they are more or less effective. To this end, we designed a method based on state-of-the-art classifiers applied to frequencies of opcodes ngrams. Then, we experimentally evaluated it on a recent dataset composed of 11120 applications, 5560 of which are malware belonging to several different families. Results show that an accuracy of 97% can be obtained on the average, whereas perfect detection rate is achieved for more than one malware family.
  • Keywords
    "Malware","Androids","Humanoid robots","Smart phones","Payloads","Mobile communication","Servers"
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2015 10th International Conference on
  • Type

    conf

  • DOI
    10.1109/ARES.2015.57
  • Filename
    7299934