Profiling CPU Behavior for Detection of Android Ransomware

Reeve Cabral, J. Todd McDonald, L.M. Hively, Ryan Benton · SoutheastCon 2022 · 2022

Android devices continue to dominate the market for global smartphone users, thus making them an ideal target for malicious software developers. In the past, side-channel attacks have been used for malicious purposes where attackers monitor system data such as power consumption, electromagnetic emissions, and CPU timing to infer sensitive user information. Likewise, researchers have begun to use mathematical models and machine learning techniques on side-channel data as a means to detect malicious activity or malware. In this paper we look at an alternative method for malware detection using side-channel analysis of CPU frequency data on Android smartphones. We perform a case-study analysis to validate feasibility of the technique and use a nonlinear phase space analysis (NLPSA) for detecting anomalous behavior based on power variations. Our study looks at a single ransomware artifact (WannaLocker) evaluated on a single Android device and operating system. As a contribution, we are the first to utilize the Perfetto system tracing tool as a potential data provider, which now comes standard on platforms since Android 9 Pie OS. Our case study results show that our NLPSA approach can classify and detect execution of the ransomware sample on a real Android device with perfect prediction accuracy in training, thus giving an initial validation to the approach.

Read the paper · More papers on PaperTik