Visible to the public A Framework for Automatic Anomaly Detection in Mobile Applications

TitleA Framework for Automatic Anomaly Detection in Mobile Applications
Publication TypeConference Paper
Year of Publication2016
AuthorsBaluda, Mauro, Pistoia, Marco, Castro, Paul, Tripp, Omer
Conference NameProceedings of the International Conference on Mobile Software Engineering and Systems
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4178-3
Keywordsanomaly detection, Human Behavior, Metrics, mobile, pubcrawl, Resiliency, Scalability, threat mitigation
AbstractIt is standard practice in enterprises to analyze large amounts of logs to detect software failures and malicious behaviors. Mobile applications pose a major challenge to centralized monitoring as network and storage limitations prevent fine-grained logs to be stored and transferred for off-line analysis. In this paper we introduce EMMA, a framework for automatic anomaly detection that enables security analysis as well as in-the-field quality assurance for enterprise mobile applications, and incurs minimal overhead for data exchange with a back-end monitoring platform. EMMA instruments binary applications with a lightweight anomaly-detection layer that reveals failures and security threats directly on mobile devices, thus enabling corrective measures to be taken promptly even when the device is disconnected. In our empirical evaluation, EMMA detected failures in unmodified Android mobile applications.
URLhttp://doi.acm.org/10.1145/2897073.2897718
DOI10.1145/2897073.2897718
Citation Keybaluda_framework_2016