Is It Safe? Identifying Malicious Apps Through the Use of Metadata and Inter-Process Communication

Rodrigo Pinto Lemos, Tiago Heinrich, Carlos Maziero, Newton C. Will · 2022 IEEE International Systems Conference (SysCon) · 2022

In recent years, the growth in the number of threats on Android has contributed to increasing user awareness and concern about security-related concepts. Due to the predominance of Android, the attacks present on the platform have also evolved, and new strategies for identifying threats are needed. A popular way to identify threats is the use of intrusion detection systems, which can exploit different strategies to carry out threat identification. Static analysis strategy aims to identify malicious apps by scanning their source code, and dynamic analysis uses the behavior monitor approach to classify benign and malicious apps. These two strategies can also be combined in a hybrid approach. This paper focuses on a hybrid strategy to identify threats in Android systems through the use of static metadata extracted from applications and dynamic data from inter-process communication, in order to train machine learning models to perform threat identification. Three machine learning algorithms were used to verify the efficacy of our strategy. Our approach showed to be viable, with the results presenting an identification rate of around 87%, demonstrating that the proposed model has benefits in identifying threats in Android mobile devices. We also point out attributes that differ between malicious and benign apps and highlight the impact on the use of inter-process communication to identify threats.

Read the paper · More papers on PaperTik