Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Andro-Dumpsys: Anti-malware system based on the similarity of malware creator and malware centric information

Full metadata record
DC Field Value Language
dc.contributor.authorJang, Jae-wook-
dc.contributor.authorKang, Hyunjae-
dc.contributor.authorWoo, Jiyoung-
dc.contributor.authorMohaisen, Aziz-
dc.contributor.authorKim, Huy Kang-
dc.date.accessioned2021-09-04T00:17:00Z-
dc.date.available2021-09-04T00:17:00Z-
dc.date.created2021-06-18-
dc.date.issued2016-05-
dc.identifier.issn0167-4048-
dc.identifier.urihttps://scholar.korea.ac.kr/handle/2021.sw.korea/88832-
dc.description.abstractWith the fast growth in mobile technologies and the accompanied rise of the integration of such technologies into our everyday life, mobile security is viewed as one of the most prominent areas and is being addressed accordingly. For that, and especially to address the threat associated with malware, various malware-centric analysis methods are developed in the literature to identify, classify, and defend against mobile threats and malicious actors. However, along with this development, anti-malware analysis techniques, such as packing, dynamic loading, and dex encryption, have seen wide adoption, making existing malware-centric analysis methods less effective. In this paper, we propose a feature-rich hybrid anti-malware system, called Andro-Dumpsys, which leverages volatile memory acquisition for accurate malware detection and classification. Andro-Dumpsys is based on similarity matching of malware creator-centric and malware-centric information. Using Andro-Dumpsys, we detect and classify malware samples into similar behavior groups by exploiting their footprints, which are equivalent to unique behavior characteristics. Our experimental results demonstrate that Andro-Dumpsys is scalable, and performs well in detecting malware and classifying malware families with low false positives and false negatives, and is capable of responding zero-day threats. (C) 2016 Elsevier Ltd. All rights reserved.-
dc.languageEnglish-
dc.language.isoen-
dc.publisherELSEVIER ADVANCED TECHNOLOGY-
dc.titleAndro-Dumpsys: Anti-malware system based on the similarity of malware creator and malware centric information-
dc.typeArticle-
dc.contributor.affiliatedAuthorKim, Huy Kang-
dc.identifier.doi10.1016/j.cose.2015.12.005-
dc.identifier.scopusid2-s2.0-84954211474-
dc.identifier.wosid000372764600008-
dc.identifier.bibliographicCitationCOMPUTERS & SECURITY, v.58, pp.125 - 138-
dc.relation.isPartOfCOMPUTERS & SECURITY-
dc.citation.titleCOMPUTERS & SECURITY-
dc.citation.volume58-
dc.citation.startPage125-
dc.citation.endPage138-
dc.type.rimsART-
dc.type.docTypeArticle-
dc.description.journalClass1-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalWebOfScienceCategoryComputer Science, Information Systems-
dc.subject.keywordAuthorVolatile memory acquisition-
dc.subject.keywordAuthorSimilarity-
dc.subject.keywordAuthorMalware creator centric information-
dc.subject.keywordAuthorMobile malware-
dc.subject.keywordAuthorAndroid-
Files in This Item
There are no files associated with this item.
Appears in
Collections
School of Cyber Security > Department of Information Security > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetrics

Total Views & Downloads

BROWSE