Andro-Dumpsys: Anti-malware system based on the similarity of malware creator and malware centric information. Issue 58 (May 2016)
- Record Type:
- Journal Article
- Title:
- Andro-Dumpsys: Anti-malware system based on the similarity of malware creator and malware centric information. Issue 58 (May 2016)
- Main Title:
- Andro-Dumpsys: Anti-malware system based on the similarity of malware creator and malware centric information
- Authors:
- Jang, Jae-wook
Kang, Hyunjae
Woo, Jiyoung
Mohaisen, Aziz
Kim, Huy Kang - Abstract:
- Highlights: Our system (Andro-Dumpsys) leverages volatile memory acquisition. Andro-Dumpsys leverages malware creator information and malware information. Andro-Dumpsys is anti-malware system based on similarity matching of footprints. Andro-Dumpsys is capable of detecting zero-day threats. Graphical Abstract: Abstract: With the fast growth in mobile technologies and the accompanied rise of the integration of such technologies into our everyday life, mobile security is viewed as one of the most prominent areas and is being addressed accordingly. For that, and especially to address the threat associated with malware, various malware-centric analysis methods are developed in the literature to identify, classify, and defend against mobile threats and malicious actors. However, along with this development, anti-malware analysis techniques, such as packing, dynamic loading, and dex encryption, have seen wide adoption, making existing malware-centric analysis methods less effective. In this paper, we propose a feature-rich hybrid anti-malware system, called Andro-Dumpsys, which leverages volatile memory acquisition for accurate malware detection and classification. Andro-Dumpsys is based on similarity matching of malware creator-centric and malware-centric information. Using Andro-Dumpsys, we detect and classify malware samples into similar behavior groups by exploiting their footprints, which are equivalent to unique behavior characteristics. Our experimental results demonstrateHighlights: Our system (Andro-Dumpsys) leverages volatile memory acquisition. Andro-Dumpsys leverages malware creator information and malware information. Andro-Dumpsys is anti-malware system based on similarity matching of footprints. Andro-Dumpsys is capable of detecting zero-day threats. Graphical Abstract: Abstract: With the fast growth in mobile technologies and the accompanied rise of the integration of such technologies into our everyday life, mobile security is viewed as one of the most prominent areas and is being addressed accordingly. For that, and especially to address the threat associated with malware, various malware-centric analysis methods are developed in the literature to identify, classify, and defend against mobile threats and malicious actors. However, along with this development, anti-malware analysis techniques, such as packing, dynamic loading, and dex encryption, have seen wide adoption, making existing malware-centric analysis methods less effective. In this paper, we propose a feature-rich hybrid anti-malware system, called Andro-Dumpsys, which leverages volatile memory acquisition for accurate malware detection and classification. Andro-Dumpsys is based on similarity matching of malware creator-centric and malware-centric information. Using Andro-Dumpsys, we detect and classify malware samples into similar behavior groups by exploiting their footprints, which are equivalent to unique behavior characteristics. Our experimental results demonstrate that Andro-Dumpsys is scalable, and performs well in detecting malware and classifying malware families with low false positives and false negatives, and is capable of responding zero-day threats. … (more)
- Is Part Of:
- Computers & security. Issue 58(2016)
- Journal:
- Computers & security
- Issue:
- Issue 58(2016)
- Issue Display:
- Volume 58, Issue 58 (2016)
- Year:
- 2016
- Volume:
- 58
- Issue:
- 58
- Issue Sort Value:
- 2016-0058-0058-0000
- Page Start:
- 125
- Page End:
- 138
- Publication Date:
- 2016-05
- Subjects:
- Volatile memory acquisition -- Similarity -- Malware creator centric information -- Mobile malware -- Android
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2015.12.005 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 1803.xml