R-PackDroid: API package-based characterization and detection of mobile ransomware

MAIORCA, DAVIDE;GIACINTO, GIORGIO;
2017-01-01

Abstract

Ransomware has become a serious and concrete threat for mobile platforms and in particular for Android. In this paper, we propose R-PackDroid, a machine learning system for the detection of Android ransomware. Differently to previous works, we leverage information extracted from system API packages, which allow to characterize applications without specific knowledge of user-defined content such as the application language or strings. Results attained on very recent data show that it is possible to detect Android ransomware and to distinguish it from generic malware with very high accuracy. Moreover, we used R-PackDroid to flag applications that were detected as ransomware with very low confidence by the VirusTotal service. In this way, we were able to correctly distinguish true ransomware from false positives, thus providing valuable help for the analysis of these malicious applications.
2017
Inglese
SAC '17: Proceedings of the Symposium on Applied Computing
9781450344869
ACM
STATI UNITI D'AMERICA
1718
1723
6
32nd Annual ACM Symposium on Applied Computing, SAC 2017
Contributo
Esperti anonimi
3-7 Aprile 2017
Marrakech, Morocco
internazionale
scientifica
no
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Maiorca, Davide; Mercaldo, Francesco; Giacinto, Giorgio; Visaggio, Corrado Aaron; Martinelli, Fabio
273
5
4.1 Contributo in Atti di convegno
reserved
info:eu-repo/semantics/conferencePaper
Files in This Item:
File Size Format  
SAC2017-R-PackDroid-printed.pdf

Solo gestori archivio

Type: versione editoriale
Size 726.01 kB
Format Adobe PDF
726.01 kB Adobe PDF & nbsp; View / Open   Request a copy

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie