DocumentCode
2898808
Title
Static Analysis of Executables for Collaborative Malware Detection on Android
Author
Schmidt, Aubrey-Derrick ; Bye, Rainer ; Schmidt, Hans-Gunther ; Clausen, Jan ; Kiraz, Osman ; Yüksel, Kamer A. ; Camtepe, Seyit A. ; Albayrak, Sahin
Author_Institution
DAI Lab., Tech. Univ. Berlin, Berlin, Germany
fYear
2009
fDate
14-18 June 2009
Firstpage
1
Lastpage
5
Abstract
Smartphones are getting increasingly popular and several malwares appeared targeting these devices. General countermeasures to smartphone malwares are currently limited to signature-based antivirus scanners which efficiently detect known malwares, but they have serious shortcomings with new and unknown malwares creating a window of opportunity for attackers. As smartphones become host for sensitive data and applications, extended malware detection mechanisms are necessary complying with the corresponding resource constraints. The contribution of this paper is twofold. First, we perform static analysis on the executables to extract their function calls in Android environment using the command readelf. Function call lists are compared with malware executables for classifying them with PART, Prism and Nearest Neighbor Algorithms. Second, we present a collaborative malware detection approach to extend these results. Corresponding simulation results are presented.
Keywords
cellular radio; groupware; invasive software; mobile computing; mobile handsets; Android environment; PART; collaborative malware detection; prism and nearest neighbor algorithms; signature-based antivirus scanners; smartphones; static analysis; Batteries; Collaboration; Collaborative work; Communications Society; Computer worms; Data security; Information security; Intrusion detection; Learning systems; Mobile computing;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, 2009. ICC '09. IEEE International Conference on
Conference_Location
Dresden
ISSN
1938-1883
Print_ISBN
978-1-4244-3435-0
Electronic_ISBN
1938-1883
Type
conf
DOI
10.1109/ICC.2009.5199486
Filename
5199486
Link To Document