DocumentCode
687583
Title
On behavior-based detection of malware on Android platform
Author
Yu Wei ; Hanlin Zhang ; Linqiang Ge ; Hardy, Rommie
Author_Institution
Towson Univ., Towson, MD, USA
fYear
2013
fDate
9-13 Dec. 2013
Firstpage
814
Lastpage
819
Abstract
Because of exponential growth in smart mobile devices, malware attacks on smart mobile devices have been growing and pose serious threats to mobile device users. To address this issue, we develop a malware detection system, which uses a behavior-based detection approach to deal with the detection of a large number of unknown malware. To accurately detect malware, we examine system calls to capture the runtime behavior of software, which interacts with an operating system and adopt machine learning approaches such as Support Vector Machine (SVM) and Naive Bayes learning schemes to learn the dynamic behavior of software execution. Using real-world malware and benign samples, we conduct experiments on Android devices and evaluate the effectiveness of our developed system in terms of learning algorithms, the size of training set, the length of n-grams, and the overhead in training and detection processes. Our experimental data demonstrates the effectiveness of our proposed detection system to detect malware.
Keywords
Bayes methods; computer network security; invasive software; learning (artificial intelligence); smart phones; support vector machines; Android devices; Android platform; SVM schemes; behavior-based detection approach; dynamic behavior; learning algorithms; machine learning approaches; malware attacks; malware detection system; naive Bayes learning schemes; operating system; smart mobile devices; software execution; support vector machine schemes; Androids; Humanoid robots; Machine learning algorithms; Malware; Software; Support vector machines; Training; Android; Machine Learning; Malware Detection; System Calls;
fLanguage
English
Publisher
ieee
Conference_Titel
Global Communications Conference (GLOBECOM), 2013 IEEE
Conference_Location
Atlanta, GA
Type
conf
DOI
10.1109/GLOCOM.2013.6831173
Filename
6831173
Link To Document