【24h】

Identifying Unknown Android Malware with Feature Extractions and Classification Techniques

机译:使用特征提取和分类技术识别未知的Android恶意软件

获取原文

摘要

Android malware unfortunately have little difficulty to sneak in marketplaces. While known malware and their variants are nowadays quite well detected by antivirus scanners, new unknown malware, which are fundamentally different from others (e.g. "0-day"), remain an issue. To discover such new malware, the SherlockDroid framework filters masses of applications and only keeps the most likely to be malicious for future inspection by antivirus teams. Apart from crawling applications from marketplaces, SherlockDroid extracts code-level features, and then classifies unknown applications with Alligator. Alligator is a classification tool that efficiently and automatically combines several classification algorithms. To demonstrate the efficiency of our approach, we have extracted properties and classified over 600,000 applications during two crawling campaigns in July 2014 and October 2014, with the detection of one new malware, Android/Odpa.A!tr.spy, and two new riskware. With other findings, this increases SherlockDroid's "Hall of Shame" to 9 totally unknown malware and potentially unwanted applications.
机译:不幸的是,Android恶意软件在市场上潜行几乎没有困难。尽管当今已知的恶意软件及其变种已被防病毒扫描程序很好地检测到,但是与其他恶意软件根本不同的新的未知恶意软件(例如“ 0天”)仍然是一个问题。为了发现这种新的恶意软件,SherlockDroid框架过滤了大量的应用程序,仅保留最有可能是恶意的,以供防病毒团队将来检查。除了从市场上搜寻应用程序外,SherlockDroid还提取代码级功能,然后使用Alligator对未知的应用程序进行分类。鳄鱼皮是一种分类工具,可以有效地自动组合几种分类算法。为了证明我们方法的效率,我们在2014年7月和2014年10月的两次抓取活动中提取了属性并分类了600,000个应用程序,并检测到一种新的恶意软件Android / Odpa.A!tr.spy和两种新的风险软件。 。结合其他发现,这将SherlockDroid的“耻辱大厅”增加到9种完全未知的恶意软件和可能有害的应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号