作者: Ludovic Apvrille , Axelle Apvrille
DOI: 10.1109/TRUSTCOM-BIGDATASE-ISPA.2015.373
关键词:
摘要: Android malware unfortunately have little difficulty to sneak in marketplaces. While known and their variants are nowadays quite well detected by antivirus scanners, new unknown malware, which fundamentally different from others (e.g. "0-day"), remain an issue. To discover such the SherlockDroid framework filters masses of applications only keeps most likely be malicious for future inspection teams. Apart crawling marketplaces, extracts code-level features, then classifies with Alligator. Alligator is a classification tool that efficiently automatically combines several algorithms. demonstrate efficiency our approach, we extracted properties classified over 600,000 during two campaigns July 2014 October 2014, detection one Android/Odpa.A!tr.spy, riskware. With other findings, this increases SherlockDroid's "Hall Shame" 9 totally potentially unwanted applications.