• DocumentCode
    2898808
  • Title

    Static Analysis of Executables for Collaborative Malware Detection on Android

  • Author

    Schmidt, Aubrey-Derrick ; Bye, Rainer ; Schmidt, Hans-Gunther ; Clausen, Jan ; Kiraz, Osman ; Yüksel, Kamer A. ; Camtepe, Seyit A. ; Albayrak, Sahin

  • Author_Institution
    DAI Lab., Tech. Univ. Berlin, Berlin, Germany
  • fYear
    2009
  • fDate
    14-18 June 2009
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Smartphones are getting increasingly popular and several malwares appeared targeting these devices. General countermeasures to smartphone malwares are currently limited to signature-based antivirus scanners which efficiently detect known malwares, but they have serious shortcomings with new and unknown malwares creating a window of opportunity for attackers. As smartphones become host for sensitive data and applications, extended malware detection mechanisms are necessary complying with the corresponding resource constraints. The contribution of this paper is twofold. First, we perform static analysis on the executables to extract their function calls in Android environment using the command readelf. Function call lists are compared with malware executables for classifying them with PART, Prism and Nearest Neighbor Algorithms. Second, we present a collaborative malware detection approach to extend these results. Corresponding simulation results are presented.
  • Keywords
    cellular radio; groupware; invasive software; mobile computing; mobile handsets; Android environment; PART; collaborative malware detection; prism and nearest neighbor algorithms; signature-based antivirus scanners; smartphones; static analysis; Batteries; Collaboration; Collaborative work; Communications Society; Computer worms; Data security; Information security; Intrusion detection; Learning systems; Mobile computing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2009. ICC '09. IEEE International Conference on
  • Conference_Location
    Dresden
  • ISSN
    1938-1883
  • Print_ISBN
    978-1-4244-3435-0
  • Electronic_ISBN
    1938-1883
  • Type

    conf

  • DOI
    10.1109/ICC.2009.5199486
  • Filename
    5199486