Android smartphones play a vital role in managing Internet of Things (IoT) devices through various applications. However, some of these applications are maliciously repackaged versions of legitimate apps, posing significant security risks. Machine learning (ML) classifiers are now widely used for malware detection, requiring relevant static and dynamic features to accurately identify malicious behavior. This chapter examines the limitations of current static and dynamic malware detection methods and suggests system call sequence analysis techniques to address these challenges. Since an application’s malicious actions are often reflected in its system call sequences, these sequences are considered optimal features for ML-based malware detection. However, many existing system call-based methods face several issues, including high feature vector dimensionality, complex classifier training, large dataset requirements, and limited ability to detect unknown, obfuscated, and adversarial malware samples. This chapter explores recent advances in malware detection, presenting innovative mechanisms that combine system call subsequence analysis with graph feature analysis to improve detection accuracy and efficiency. These approaches address limitations in traditional methods by using system call patterns and graph-based features, which together capture key indicators of malicious behavior, enhance classifier performance, and reduce computational demands, making them highly effective in detecting diverse types of malware in IoT and Android applications.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Malware in the Connected World: Advanced Detection Techniques Using System Calls and Graph Analysis

  • Roopak Surendran,
  • Tony Thomas

摘要

Android smartphones play a vital role in managing Internet of Things (IoT) devices through various applications. However, some of these applications are maliciously repackaged versions of legitimate apps, posing significant security risks. Machine learning (ML) classifiers are now widely used for malware detection, requiring relevant static and dynamic features to accurately identify malicious behavior. This chapter examines the limitations of current static and dynamic malware detection methods and suggests system call sequence analysis techniques to address these challenges. Since an application’s malicious actions are often reflected in its system call sequences, these sequences are considered optimal features for ML-based malware detection. However, many existing system call-based methods face several issues, including high feature vector dimensionality, complex classifier training, large dataset requirements, and limited ability to detect unknown, obfuscated, and adversarial malware samples. This chapter explores recent advances in malware detection, presenting innovative mechanisms that combine system call subsequence analysis with graph feature analysis to improve detection accuracy and efficiency. These approaches address limitations in traditional methods by using system call patterns and graph-based features, which together capture key indicators of malicious behavior, enhance classifier performance, and reduce computational demands, making them highly effective in detecting diverse types of malware in IoT and Android applications.