kirancodes.me
To Proof Maintenance & Beyond!

Apposcopy: semantics-based detection of Android malware through static analysis

Yu Feng, Saswat Anand, Isil Dillig, Alex Aiken

Abstract

We present Apposcopy, a new semantics-based approach for identifying a prevalent class of Android malware that steals private user information. Apposcopy incorporates (i) a high-level language for specifying signatures that describe semantic characteristics of malware families and (ii) a static analysis for deciding if a given application matches a malware signature. The signature matching algorithm of Apposcopy uses a combination of static taint analysis and a new form of program representation called Inter-Component Call Graph to efficiently detect Android applications that have certain control- and data-flow properties. We have evaluated Apposcopy on a corpus of real-world Android applications and show that it can effectively and reliably pinpoint malicious applications that belong to certain malware families.

BibTeX
@inproceedings{Feng-al:FSE14,
  author    = {Yu Feng and
               Saswat Anand and
               Isil Dillig and
               Alex Aiken},
  title     = {Apposcopy: semantics-based detection of Android malware through static analysis},
  booktitle = {FSE},
  pages     = {576--587},
  publisher = {{ACM}},
  year      = {2014},
}

Related papers