| Literature DB >> 26543718 |
Xiaolei Wang1, Yuexiang Yang1, Yingzhi Zeng2.
Abstract
As the dominator of the Smartphone operating system market, consequently android has attracted the attention of s malware authors and researcher alike. The number of types of android malware is increasing rapidly regardless of the considerable number of proposed malware analysis systems. In this paper, by taking advantages of low false-positive rate of misuse detection and the ability of anomaly detection to detect zero-day malware, we propose a novel hybrid detection system based on a new open-source framework CuckooDroid, which enables the use of Cuckoo Sandbox's features to analyze Android malware through dynamic and static analysis. Our proposed system mainly consists of two parts: anomaly detection engine performing abnormal apps detection through dynamic analysis; signature detection engine performing known malware detection and classification with the combination of static and dynamic analysis. We evaluate our system using 5560 malware samples and 6000 benign samples. Experiments show that our anomaly detection engine with dynamic analysis is capable of detecting zero-day malware with a low false negative rate (1.16 %) and acceptable false positive rate (1.30 %); it is worth noting that our signature detection engine with hybrid analysis can accurately classify malware samples with an average positive rate 98.94 %. Considering the intensive computing resources required by the static and dynamic analysis, our proposed detection system should be deployed off-device, such as in the Cloud. The app store markets and the ordinary users can access our detection system for malware detection through cloud service.Entities:
Keywords: Android; Anomaly detection; Classification; CuckooDroid; Dynamic analysis; Mobile cloud service; Mobile malware detection; Signature detection; Static analysis
Year: 2015 PMID: 26543718 PMCID: PMC4628031 DOI: 10.1186/s40064-015-1356-1
Source DB: PubMed Journal: Springerplus ISSN: 2193-1801
Fig. 1System overview
Fig. 2Framework of Cuckoodroid
Categories and numbers of extracted features
| Source | Category | #Feature |
|---|---|---|
| Dynamic | File operations | 19,038 |
| Static and dynamic | Signatures | 1283 |
| Dynamic | Registered_receivers | 8334 |
| Dynamic | Reflection_calls | 14,799 |
| Static | Used/required permissions | 1267 |
| Static and dynamic | SMS, phone, contacts | 1493 |
| Static | Application components | 21,523 |
| Static and dynamic | Dynamic code loading | 916 |
| Static and dynamic | Crypto operation | 41 |
| Dynamic | Data_leak | 828 |
| Dynamic | Commands | 937 |
| Static and dynamic | Network activity | 37,734 |
| Static | The use of special API | 20,162 |
| Dynamic | System properties | 13,081 |
Top 20 malware families in our dataset
| Id | Family | # | Id | Family |
|
|---|---|---|---|---|---|
| A | FakeInstaller | 925 | K | Adrd | 91 |
| B | DroidKungFu | 667 | L | Droiddreru | 81 |
| C | Plankton | 625 | M | LinuxLotoor | 70 |
| D | Opfake | 613 | N | GoldDream | 69 |
| E | GingerMaster | 339 | O | MobileTx | 69 |
| F | BaseBridge | 330 | P | FakeRun | 61 |
| G | Iconosys | 152 | Q | SendPay | 59 |
| H | Kmin | 147 | R | Gappusin | 58 |
| I | FakeDoc | 132 | S | Imlog | 43 |
| J | Geinimi | 92 | T | SMSreg | 41 |
Fig. 3The confusion matrix of anomaly detection
Fig. 4The ROC curve of anomaly detection
Fig. 5The ROC curve of other detection methods
The detection rate of top 20 malware families
| Family | Detection rate (%) | Family | Detection rate (%) |
|---|---|---|---|
| A | 99.71 | K | 100 |
| B | 100 | L | 100 |
| C | 100 | M | 100 |
| D | 100 | N | 100 |
| E | 100 | O | 100 |
| F | 100 | P | 100 |
| G | 100 | Q | 100 |
| H | 100 | R | 100 |
| I | 100 | S | 100 |
| J | 100 | T | 100 |
Fig. 6The detection performance of AV scanners and ours
Fig. 7Linear SVC-L1 based multi-family classifie
Fig. 8Linear SVC- L2 based multi-family classifier
Fig. 9LinearSVM based multi-family classifier
Fig. 10The classification performance of three methods
Fig. 11The detailed analysis report