Behavior grouping of Android malware family
Shun-Wen Hsiao, Yeali S. Sun, Meng Chang Chen · 2016
Malicious apps may install unwanted program or gather sensitive information from mobile devices. We notice Android apps fork several threads to accomplish a complex task intrinsically, and so does Android malware, that makes security experts difficult to analyze them without knowing their structure. In this paper, we propose an analysis scheme to group and analyze Android malware based on their dynamic behaviors, and to identify the behaviors of a malware family. In addition, we apply the techniques of phylogenetic tree, significant principal components and dot matrix on different malware families to demonstrate their behavioral correlations. The proposed methods can automatically discover similar behaviors of different malware groups, extract the characteristics of each malware group, and provide visualized information based on runtime behaviors. We anticipate the grouping result and the structure of malware family are important and essential for further malware behavior analysis researches.