首页> 外文期刊>Computers & Security >Identifying android malicious repackaged applications by thread-grained system call sequences
【24h】

Identifying android malicious repackaged applications by thread-grained system call sequences

机译:通过线程粒度的系统调用序列识别android恶意重新打包的应用程序

获取原文
获取原文并翻译 | 示例

摘要

Android security has become highly desirable since adversaries can easily repackage malicious codes into various benign applications and spread these malicious repackaged applications (MRAs). Most MRA detection mechanisms on Android focus on detecting a specific family of MRAs or requiring the original benign application to compare with the malicious ones. This work proposes a new mechanism, SCSdroid (System Call Sequence Droid), which adopts the thread-grained system call sequences activated by applications. The concept is that even if MRAs can be camouflaged as benign applications, their malicious behavior would still appear in the system call sequences. SCSdroid extracts the truly malicious common subsequences from the system call sequences of MRAs belonging to the same family. Therefore, these extracted common subsequences can be used to identify any evaluated application without requiring the original benign application. Experimental results show that SCSdroid falsely detected only two applications among 100 evaluated benign applications, and falsely detected only one application among 49 evaluated malicious applications. As a result, SCSdroid achieved up to 95.97% detection accuracy, i.e., 143 correct detections among 149 applications.
机译:由于攻击者可以轻松地将恶意代码重新打包到各种良性应用程序中,并传播这些恶意重新打包的应用程序(MRA),因此Android安全性已成为人们所迫切需要的。 Android上的大多数MRA检测机制都专注于检测特定的MRA系列,或要求原始的良性应用程序与恶意应用程序进行比较。这项工作提出了一种新的机制SCSdroid(系统调用序列Droid),它采用了由应用程序激活的线程粒度系统调用序列。这个概念是,即使MRA可以伪装成良性应用程序,其恶意行为仍会出现在系统调用序列中。 SCSdroid从属于同一家族的MRA的系统调用序列中提取真正恶意的公共子序列。因此,这些提取的公共子序列可以用于标识任何评估的应用程序,而无需原始的良性应用程序。实验结果表明,SCSdroid在100个评估为良性的应用程序中仅错误地检测到两个应用程序,而在49个评估为恶意的应用程序中仅错误地检测到一个应用程序。结果,SCSdroid达到了高达95.97%的检测精度,即在149个应用程序中进行了143次正确检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号