Title :
Android Malware Detection via a Latent Network Behavior Analysis
Author :
Wei, Te-En ; Mao, Ching-Hao ; Jeng, Albert B. ; Lee, Hahn-Ming ; Wang, Horng-Tzer ; Wu, Dong-Jie
Author_Institution :
Dept. of Comput. Sci. & Inf. Eng., Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
Abstract :
The rapid growth of smartphones has lead to a renaissance for mobile application services. Android and iOS now as the most popular smartphone platforms offer a public marketplace respectively, the Android Market and App Store- but operate with dramatically different approaches to prevent malware on their devices. In Android platform, developer not only can directly deliver their apps on the Android market without strict review process, but also is capable to put the non-official verified apps marketplace (i.e., Applanet, AppBrain and so on). In this study, we purpose an automatic Android malware detection mechanism based on the result from sandbox. We leverage network spatial feature extraction of Android apps and independent component analysis (ICA) to find the intrinsic domain name resolution behavior of Android malware. The proposed mechanism that identifies the Android malware can achieve in automatic way. For evaluation the proposed approach, the public Android malware apps dataset and popular benign apps collected from Android Market are used for evaluating the effectiveness in analyzing the grouping ability and the effectiveness of identifying the Android malware. The proposed approach successfully identifies malicious Android Apps close to 100% accuracy, precision and recall rate.
Keywords :
Linux; feature extraction; independent component analysis; invasive software; mobile computing; smart phones; Android Market; Android malware detection; App Store; ICA; automatic Android malware identification; automatic malware detection; iOS; independent component analysis; intrinsic domain name resolution behavior determination; latent network behavior analysis; mobile application services; network spatial feature extraction; public Android malware app dataset; sandbox; smart phones; Androids; Feature extraction; Humanoid robots; IP networks; Malware; Smart phones; Domain Name; Independent Component Analysis; Latent Behavior; Machine Learning; Malware;
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
Conference_Location :
Liverpool
Print_ISBN :
978-1-4673-2172-3
DOI :
10.1109/TrustCom.2012.91