earticle

논문검색

An API Calls Monitoring-based Method for Effectively Detecting Malicious Repackaged Applications

초록

영어

The number of mobile applications on Android platform has largely increased in recent years. The security problems, as one of the outcomes induced by the popularity of Android, become more and more critical. Malicious repackaged applications (MRAs) perform malicious behaviors through malware developers embedding malicious codes into the benign origin applications (BOAs), which threat the security of users’ finance and privacy. In this paper, a method based on API calls monitoring is proposed to effectively detect MRAs. We discuss the characteristics of behaviors and analyze the differences in API calls between MRAs and their BOAs. A MRA detection model is established, which builds up the super-sphere for each BOA via a SVDD algorithm. The model can detect the abnormal behaviors of MRAs which deviate the normal behaviors of corresponding BOAs. Experiments are carried out on imitated and real MRAs, where the results demonstrate the effectiveness of our method for detecting the singly and multiply contaminated BOAs.

목차

Abstract
 1. Introduction
 2. Related Work
 3. MRA Detection Model
  3.1. Feature Extraction
  3.2. Behavior Description
  3.3. MRA Detection Process
 4. Experiment Results and Analysis
  4.1. Imitated Malicious Repackaged Applications
  4.2. Real Malicious Repackaged Applications
 5. Conclusion
 Acknowledgements
 References

저자정보

  • Wenhao Fan School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China, Beijing Key Laboratory of Work Safety Intelligent Monitoring, Beijing University of Posts and Telecommunications, Beijing 100876, China
  • Yuan’an Liu School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China, Beijing Key Laboratory of Work Safety Intelligent Monitoring, Beijing University of Posts and Telecommunications, Beijing 100876, China
  • Bihua Tang School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China, Beijing Key Laboratory of Work Safety Intelligent Monitoring, Beijing University of Posts and Telecommunications, Beijing 100876, China

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.