@inproceedings{aa33d533ec584f5197049f9ea643157d,
title = "Combining crowd contributions with machine learning todetect malicious mobile apps",
abstract = "Android is undoubtedly becoming the most popular smartphone platform. The popularity of Android, unfortunately, has also made the devices become the target of malware. Most of existing malicious mobile apps feature stealthy operations such as collecting user privacy, sending premium SMS messages and making unauthorized http connections with no legal notice to the a ected user. However, transmission of sensitive data cannot indicate malicious behavior because some benign applications also need sensitive data to improve the user experience. Existing malware detection approaches focus on static or dynamic analysis without crowd user contributions. In this paper, we propose a novel technique which combining crowd contributions with machine learning to detect malicious mobile apps. We model privacy transmission as user-determined and undetermined with the help of real user decisions based on crowdsourcing. We apply static analysis to extract application basic information such as permissions and suspicious API calls. Then we use dynamic instrumentation technique to trace real API calls at runtime and collect the crowd user decisions to the prompted sensitive data transmission. Finally, we employ several di erent learning-based algorithms, such as SVM, Bayesian Network, Decision Tree and KNN to detect malicious apps. Experiments with 100 real application samples show that our system was capable of detecting malicious mobile apps: our system can detect 85\% to 97\% of the malware with low false positive rate.",
keywords = "Android security, Crowdsourcing, Dynamic analysis, Machine learning, Malware detection, Static analysis",
author = "Dahai Yao and Hailong Sun and Xudong Liu",
note = "Publisher Copyright: {\textcopyright} 2015 ACM.; 7th Asia-Pacific Symposium on Internetware, Internetware 2015 ; Conference date: 06-11-2015",
year = "2015",
month = nov,
day = "6",
doi = "10.1145/2875913.2875941",
language = "英语",
series = "ACM International Conference Proceeding Series",
publisher = "Association for Computing Machinery ",
pages = "120--123",
booktitle = "7th Asia-Pacific Symposium on Internetware, Internetware 2015 - Proceedings",
address = "美国",
}