Visible to the public Analysis of Android Malware Family Characteristic Based on Isomorphism of Sensitive API Call Graph

TitleAnalysis of Android Malware Family Characteristic Based on Isomorphism of Sensitive API Call Graph
Publication TypeConference Paper
Year of Publication2017
AuthorsZhou, H., Zhang, W., Wei, F., Chen, Y.
Conference Name2017 IEEE Second International Conference on Data Science in Cyberspace (DSC)
KeywordsAlgorithm design and analysis, android, Android (operating system), Android Malware family characteristic analysis, Androids, application program interfaces, call graph structures, graph similarity metric, graph theory, Heuristic algorithms, Human Behavior, Humanoid robots, invasive software, Libraries, Malware, malware analysis, malware instances, Metrics, Mobile communication, privacy, pubcrawl, resilience, Resiliency, sensitive API call graph, static analysis approach

The analysis of multiple Android malware families indicates malware instances within a common malware family always have similar call graph structures. Based on the isomorphism of sensitive API call graph, we propose a method which is used to construct malware family features via combining static analysis approach with graph similarity metric. The experiment is performed on a malware dataset which contains 1326 malware samples from 16 different malware families. The result shows that the method can differentiate distinct malware family features and divide suspect malware samples into corresponding families with a high accuracy of 96.77% overall and even defend a certain extent of obfuscation.

Citation Keyzhou_analysis_2017