首页> 外文会议>2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications >Droid Analytics: A Signature Based Analytic System to Collect, Extract, Analyze and Associate Android Malware
【24h】

Droid Analytics: A Signature Based Analytic System to Collect, Extract, Analyze and Associate Android Malware

机译:Droid Analytics:一种基于签名的分析系统,用于收集,提取,分析和关联Android恶意软件

获取原文
获取原文并翻译 | 示例

摘要

Smartphones and mobile devices are rapidly becoming indispensable devices for many users. Unfortunately, they also become fertile grounds for hackers to deploy malware. There is an urgent need to have a "security analytic & forensic system" which can facilitate analysts to examine, dissect, associate and correlate large number of mobile applications. An effective analytic system needs to address the following questions: How to automatically collect and manage a high volume of mobile malware? How to analyze a zero-day suspicious application, and compare or associate it with existing malware families in the database? How to reveal similar malicious logic in various malware, and to quickly identify the new malicious code segment? In this paper, we present the design and implementation of DroidAnalytics, a signature based analytic system to automatically collect, manage, analyze and extract android malware. The system facilitates analysts to retrieve, associate and reveal malicious logics at the "opcode level". We demonstrate the efficacy of DroidAnalytics using 150, 368 Android applications, and successfully determine 2, 475 Android malware from 102 different families, with 327 of them being zero-day malware samples from six different families. To the best of our knowledge, this is the first reported case in showing such a large Android malware analysis/detection. The evaluation shows the DroidAnalytics is a valuable tool and is effective in analyzing malware repackaging and mutations.
机译:智能手机和移动设备正迅速成为许多用户必不可少的设备。不幸的是,它们也成为黑客部署恶意软件的沃土。迫切需要一种“安全分析和取证系统”,该系统可以帮助分析人员检查,分析,关联和关联大量移动应用程序。一个有效的分析系统需要解决以下问题:如何自动收集和管理大量的移动恶意软件?如何分析零日可疑应用程序,并将其与数据库中现有的恶意软件家族进行比较或关联?如何在各种恶意软件中揭示相似的恶意逻辑,并快速识别新的恶意代码段?在本文中,我们介绍了DroidAnalytics的设计和实现,DroidAnalytics是一个基于签名的分析系统,用于自动收集,管理,分析和提取android恶意软件。该系统有助于分析人员在“操作码级别”检索,关联和揭示恶意逻辑。我们使用150个,368个Android应用程序演示了DroidAnalytics的功效,并成功地从102个不同家族中确定了2,475个Android恶意软件,其中327个是来自六个不同家族的零日恶意软件样本。据我们所知,这是首次报告的案例,显示了如此大型的Android恶意软件分析/检测。评估显示DroidAnalytics是一个有价值的工具,可以有效地分析恶意软件的重新包装和突变。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号