Android malware classification method: Dalvik bytecode frequency analysis

  • Kang, Byeongho
  • Kang, BooJoong
  • Kim, Jungtae
  • Im, Eul Gyu
Citations

SCOPUS

31

초록

The number of Android malware is increasing with the growth of Android, so there needs to have a method to classify malware families. There are many classification methods proposed so far, but most of them are based on permission information such as the number of requested permissions and critical permissions. Since permission information cannot represent actual application behaviors and permissions are easily separated into several communicating applications, the permission based classification methods can result in false alarms. Opposed to these permission based methods, our classification method is based on applications' Bytecode that contains actual application behaviors. Each malicious application family may have some similar Bytecode and can be classified using this information. In this paper, we propose a method to classify malware families from known malware, as a pre-step of malware detection.

키워드

bytecode frequency analysisgoogle androidmalware classificationmnemonic frequency analysisrandom forestApplication behaviorsClassification methodsFrequency Analysisgoogle androidMalware classificationsMalware detectionMalware familiesRandom forestsDecision treesRobotsComputer crime
제목
Android malware classification method: Dalvik bytecode frequency analysis
저자
Kang, ByeonghoKang, BooJoongKim, JungtaeIm, Eul Gyu
DOI
10.1145/2513228.2513295
발행일
2013-10
유형
Conference Paper
저널명
Proceedings of the 2013 Research in Adaptive and Convergent Systems, RACS 2013
페이지
349 ~ 350