首页> 外文期刊>Iran Journal of Computer Science >LimonDroid: a system coupling three signature-based schemes for profiling Android malware
【24h】

LimonDroid: a system coupling three signature-based schemes for profiling Android malware

机译:Limondroid:一个系统耦合三个基于签名的方案,用于分析Android恶意软件

获取原文
获取原文并翻译 | 示例
       

摘要

Android remains an interesting target to attackers due to its openness. A contribution in the literature consists of providing similarity measurement such as fuzzy hashing to fight against code obfuscation techniques. Research works in this approach suffer from limited signature database. This work combines fuzzy hashing with YARA rules and VirusTotal signature-based schemes, to improve and consistency of the signature database. It is proposed LimonDroid, an Android system, which mimics Limon, a Desktop security tool that includes such schemes. LimonDroid has been tested with 341 malicious and 300 benign applications on a database of 12925 fuzzy-hashed malware signatures, 62 YARA malware families’ patterns and VirusTotal engine. Our approach gives a true-positive rate of 97.36%, a true negative rate of 98.33% and an accuracy of 97.82%. A comparison with similarity-based solutions reveals that LimonDroid is more efficient for users. The objective is not to propose a detection approach better than those in the literature. Instead, we aim at establishing a robust signature database able to identify malicious trends in Android apps.
机译:Android因其开放而对攻击者仍然是一个有趣的目标。文献中的贡献包括提供相似性测量,例如模糊哈希以防止代码混淆技术。这种方法的研究工作遭受了有限的签名数据库。这项工作将模糊散列与雅拉规则和基于毒素签名的方案结合起来,提高了签名数据库的提高和一致性。它是建议的瑞纳迪德,一个Android系统,模仿Limon,一个包含此类方案的桌面安全工具。在12925个模糊散列恶意软件签名,62雅马尔软件家庭模式和恶意发动机的数据库中,已经用341个恶意和300个良性应用进行了测试。我们的方法为真正阳性率为97.36%,真正的负率为98.33%,准确性为97.82%。与相似性的解决方案的比较显示,利润率对用户更有效。目标不是提出比文献中的检测方法更好。相反,我们的目标是建立一个能够识别Android应用程序中恶意趋势的强大签名数据库。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号