MDASC: Advanced Dual-Layered Code Cloning Technique for Identifying Reused Malicious Code
Yasir Glani, Paul Lo, Ke Cheng Lin · Proceedings/Proceedings of the ... International Conference on Software Engineering and Knowledge Engineering · 2024
Code cloning is a prevalent practice in software development, frequently exploited by adversaries to propagate malicious code, compromising user security and privacy.Recently proposed detection techniques often fail to identify complex clones, posing significant software integrity and security risks.In response, we introduce MDASC, an advanced dual-layered approach to detecting known Android malware through code cloning.MDASC employs method-based signature detection followed by sliding windows-based detection, effectively identifying modified and unmodified states of reused malware code, encompassing Type-I, Type-II, and Type-III (VST, ST, and MT) clones.Our comprehensive comparative study evaluates MDASC against recently proposed techniques across various code cloning detection methods, demonstrating its superiority in precision, recall, F1-score, accuracy, and efficiency.Leveraging intelligent retrieval and processing algorithms, MDASC maintains high efficiency, achieving an average detection time of 0.33 seconds for a database of 132,414 files and 13.5 million lines of code.This efficiency and effectiveness emphasize MDASC's potential for real-time security applications.MDASC represents a significant advancement in malicious code reuse detection, offering unparalleled accuracy and efficiency, thereby enhancing software security practices within the rapidly evolving Android ecosystem.