Passer à la navigation principale Passer à la recherche Passer au contenu principal

SherlockDroid: a research assistant to spot unknown malware in Android marketplaces

  • FortiGuard Labs
  • CNRS LTCI

Résultats de recherche: Contribution à un journalArticleRevue par des pairs

Résumé

With over 1,400,000 Android applications in Google Play alone, and dozens of different marketplaces, Android malware unfortunately have no difficulty to sneak in and silently spread. Known malware and their variants are nowadays quite well detected by anti-virus scanners. Nevertheless, the fundamentally new and unknown malware remain an issue. To assist research teams in the discovery of such new malware, we built an infrastructure, named SherlockDroid, whose goal is to filter out the mass of applications and only keep those which are the most likely to be malicious for future inspection by Anti-virus teams. SherlockDroid consists of marketplace crawlers, code-level property extractors and a classification tool named Alligator which decides whether the sample looks malicious or not, based on some prior learning. In our tests, we extracted properties and classified over 480K applications. During two crawling campaigns in July 2014 and October 2014, SherlockDroid crawled over 120K applications with the detection of one new malware, Android/Odpa.A!tr.spy, and two new riskware. With previous findings, this increases SherlockDroid and Alligator’s “Hall of Shame” to 8 malware and potentially unwanted applications.

langue originaleAnglais
Pages (de - à)235-245
Nombre de pages11
journalJournal of Computer Virology and Hacking Techniques
Volume11
Numéro de publication4
Les DOIs
étatPublié - 1 nov. 2015
Modification externeOui

Empreinte digitale

Examiner les sujets de recherche de « SherlockDroid: a research assistant to spot unknown malware in Android marketplaces ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation