Ali Feizollah
AndroDialysis: Analysis of Android Intent Effectiveness in Malware Detection
Feizollah, Ali; Anuar, Nor Badrul; Salleh, Rosli; Suarez-Tangil, Guillermo; Furnell, Steven
Authors
Nor Badrul Anuar
Rosli Salleh
Guillermo Suarez-Tangil
STEVEN FURNELL STEVEN.FURNELL@NOTTINGHAM.AC.UK
Professor of Cyber Security
Abstract
© 2016 Elsevier Ltd The wide popularity of Android systems has been accompanied by increase in the number of malware targeting these systems. This is largely due to the open nature of the Android framework that facilitates the incorporation of third-party applications running on top of any Android device. Inter-process communication is one of the most notable features of the Android framework as it allows the reuse of components across process boundaries. This mechanism is used as gateway to access different sensitive services in the Android framework. In the Android platform, this communication system is usually driven by a late runtime binding messaging object known as Intent. In this paper, we evaluate the effectiveness of Android Intents (explicit and implicit) as a distinguishing feature for identifying malicious applications. We show that Intents are semantically rich features that are able to encode the intentions of malware when compared to other well-studied features such as permissions. We also argue that this type of feature is not the ultimate solution. It should be used in conjunction with other known features. We conducted experiments using a dataset containing 7406 applications that comprise 1846 clean and 5560 infected applications. The results show detection rate of 91% using Android Intent against 83% using Android permission. Additionally, experiment on combination of both features results in detection rate of 95.5%.
Citation
Feizollah, A., Anuar, N. B., Salleh, R., Suarez-Tangil, G., & Furnell, S. (2017). AndroDialysis: Analysis of Android Intent Effectiveness in Malware Detection. Computers and Security, 65, 121-134. https://doi.org/10.1016/j.cose.2016.11.007
Journal Article Type | Article |
---|---|
Acceptance Date | Nov 12, 2016 |
Online Publication Date | Nov 16, 2016 |
Publication Date | Mar 1, 2017 |
Deposit Date | Sep 14, 2020 |
Publicly Available Date | Sep 14, 2020 |
Journal | Computers and Security |
Print ISSN | 0167-4048 |
Publisher | Elsevier |
Peer Reviewed | Peer Reviewed |
Volume | 65 |
Pages | 121-134 |
DOI | https://doi.org/10.1016/j.cose.2016.11.007 |
Public URL | https://nottingham-repository.worktribe.com/output/4868125 |
Publisher URL | https://www.sciencedirect.com/science/article/pii/S0167404816301602?via%3Dihub |
Files
AndroDialysis: Analysis of Android Intent Effectiveness in Malware Detection
(973 Kb)
PDF
You might also like
A suspect-oriented intelligent and automated computer forensic analysis
(2016)
Journal Article
Information security policy compliance model in organizations
(2015)
Journal Article
Continuous user authentication using multi-modal biometrics
(2015)
Journal Article
Surveying the development of biometric user authentication on mobile phones
(2014)
Journal Article
Downloadable Citations
About Repository@Nottingham
Administrator e-mail: discovery-access-systems@nottingham.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2024
Advanced Search