ClusTheDroid: Clustering Android Malware
David Korczynski · 2015
The volume of new Android malware is growing at an exponential pace. This cries for automated tools that can aid the malware analyst in dissecting the behaviours of new malicious applications. In this paper, we present ClusTheDroid, a system for clustering Android malware so as to identify malicious applications that exhibit similar behaviours. For this, ClusTheDroid extracts feature sets from profiles of reconstructed malicious Android behaviours. These feature sets serve as input to a clustering algorithm that allows for volumes larger than demanded by the anti-malware industry today. We implemented ClusTheDroid and evaluated it on real-world malware. Our results show that ClusTheDroid is competitive with existing solutions targeting similar problems on Android malware, but lacks accuracy to similar solutions that focus on PC malware. We furthermore evaluate the use of the cluster-validity measure C-index, which suggest for a more flexible approach to identifying near-optimal clusters than that of previous literature.