Machine learning on merging static and dynamic features to identify malicious mobile apps
Ming‐Yang Su, Jer-Yuan Chang, Kek-Tung Fung · 2017
The amount of Android system-targeted malware has increased dramatically in recent years, and Android has been the focus of far more malware targeting than other mobile operating systems. In order to reduce the hazards of malware, this paper proposes a malware detection system with static and dynamic app features. In terms of the static features, the permissions, native-permissions, function and priority of an app are extracted as the base of analysis. In terms of the dynamic feature, the app is executed in a sandbox emulator, and then log files are analyzed to identify behaviors that help judgment, such as sending short messages without permission, modifying system files or reading personal data. This system extracts the static and dynamic features of an app, which are then merged before the weights are adjusted appropriately. Finally, Weka is used for training to obtain the detection module. According to the experiment, an unknown malicious act is evaluated using tenfold cross validation; the proposed system achieves a 97.4% accuracy.