MineRBS: Detecting Android Malware Based on Runtime Behavior Sequence

Hao Jin, Yangyang Li, Ying Yang · 2020

The runtime behaviors performed by Android applications reflect their potential characteristics. While the implementation of a malicious attack usually requires the cooperation of multiple runtime behaviors, so mining the association between runtime behavior sequences can effectively detect unknown malicious applications. Most researchers concerned the statistical properties of a single behavior, and there was little work studying the statistical properties of the association between runtime behaviors. In this paper, we present an Android malware detection system MineRBS based on a novel sequential pattern mining method, called RB AprefixSpan (PrefixSpan Abbreviated Project Mining of Runtime Behaviors), to dig out runtime behavior associations. RB AprefixSpan algorithm could discover runtime behavior sequential patterns from known malware families and build the behavior sequential pattern database to detect ma l-ware. What's more, RB AprefixSpan algorithm uses abbreviated projection database instead of projection database in PrefixSpan to improve the spatial performance. Through experiments, we verity the correctness and effectiveness of our system.

Read the paper · More papers on PaperTik