Identifying Applications' State via System Calls Activity: A Pipeline Approach
Fatema Maasmi, Martina Morcos, Hussam Al Hamadi, Ernesto Damiani · 2021 28th IEEE International Conference on Electronics, Circuits, and Systems (ICECS) · 2021
Android is the most widespread smartphone operating system. Its popularity attracted attackers to develop all sorts of malicious applications. On the defense side, much research has been done toward identifying Android applications type and state based on their system-level behavior. Recent research has shown that some behavioral features linked to user interaction are strongly correlated with the malice of apps. Guided by these insights, we designed a Machine Learning (ML) technique to detect whether an application is currently running in the foreground or not. The technique is aimed at boosting the accuracy of behavioral malware detection by providing informative priors or context metadata on app state to malware identification models. We report that a structured ML pipeline that identifies the app prior to detecting its mode can achieve substantially higher accuracy than direct mode identification.