Skip to main navigation Skip to search Skip to main content

DroidChain: A novel malware detection method for Android based on behavior chain

  • School of Computer Science and Technology, Harbin Institute of Technology
  • National Computer Network Emergency Response Technical Team/Coordination Center of China
  • Tsinghua University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Android malware threats have recently become a real concern. The growing amount and diversity of these applications render conventional defenses largely ineffective. To fight against malware variants and zero-day malware, this paper proposes DroidChain, a malware detection method based on behavior chain model, which is composed of typical behavior processes of Android apps. Using the method, we summarize four kinds of malware models, including privacy leakage, SMS financial charge, malware installation and privilege escalation. The detection of 1260 Android applications shows that the accuracy of this method reaches 81.8%.

Original languageEnglish
Title of host publication2015 IEEE Conference on Communications and NetworkSecurity, CNS 2015
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages727-728
Number of pages2
ISBN (Electronic)9781467378765
DOIs
StatePublished - 3 Dec 2015
Externally publishedYes
Event3rd IEEE International Conference on Communications and Network Security, CNS 2015 - Florence, Italy
Duration: 28 Sep 201530 Sep 2015

Publication series

Name2015 IEEE Conference on Communications and NetworkSecurity, CNS 2015

Conference

Conference3rd IEEE International Conference on Communications and Network Security, CNS 2015
Country/TerritoryItaly
CityFlorence
Period28/09/1530/09/15

Keywords

  • Behavior Chain
  • SMS financial charge
  • malware installing
  • privacy leakage
  • privilege escalation

Fingerprint

Dive into the research topics of 'DroidChain: A novel malware detection method for Android based on behavior chain'. Together they form a unique fingerprint.

Cite this