• DocumentCode
    1875773
  • Title

    DroidExec: Root exploit malware recognition against wide variability via folding redundant function-relation graph

  • Author

    Te-En Wei ; Hahn-Ming Lee ; Hsiao-Rong Tyan ; Liao, Hong-Yuan Mark ; Jeng, Albert B. ; Jiunn-Chin Wang

  • Author_Institution
    Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
  • fYear
    2015
  • fDate
    1-3 July 2015
  • Firstpage
    161
  • Lastpage
    169
  • Abstract
    DroidExec is a novel root exploit recognition to reduce the influence of wide variability, which usually affects the Android malware detection rate, because of Android applications´s various properties. In Android, a specific malware family (e.g., root exploit malware), and thus its implementation may be influenced by the campaign it is serving, and thus producing wide variability, leading its samples to appear to match a wider range of potential families. In this paper, we propose a similarity recognition named as DroidExec, reducing wide variability via folding redundant function-relation graph based on Bipartite Graph Conceptual Matching of graph edit distance. We compute the multiple square roots for each 2×2 block in the cost matrix to conceptually cripple the wide variability. In the experiments, we measure the applications´s opcode structural similarity for clustering Android malware. Empirical validation shows that DroidExec can effectively filter surplus and various behaviors, which can improve the precision/recall rate from 82%/95% to 83%/97%, respectively.
  • Keywords
    Android (operating system); graph theory; invasive software; matrix algebra; Android malware detection rate; DroidExec; bipartite graph conceptual matching; cost matrix; folding redundant function-relation graph; graph edit distance; opcode structural similarity; root exploit malware recognition; wide variability; Androids; Bipartite graph; Electronic mail; Feature extraction; Humanoid robots; Malware; Matrix decomposition;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Communication Technology (ICACT), 2015 17th International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-8-9968-6504-9
  • Type

    conf

  • DOI
    10.1109/ICACT.2015.7224777
  • Filename
    7224777