The growing spread of malware on Android OS requires new approaches for the detection and recognition of malicious applications on mobile devices. An emerging idea is characterizing malicious behaviors in terms of energy consumption, to support the definition of Energy-aware Intrusion Detection Systems that are able to recognize malicious behaviors in terms of their energy footprint. To this aim, the energy consumption of several hardware components of a mobile device must be measured at a sufficiently fine-grained level of precision. Furthermore, the same measurements must not be energyhungry. In Android, several sources can provide energy consumption information, from high-level API to low level measurements taken directly from the battery driver. In this paper, we consider two approaches to measurements available in literature and, by measuring the consumption of a device under attack, we empirically assess their suitability to support the profiling of both benign and malicious applications in Android. Then, we propose a new approach able to overcome the limitations of the existing ones and we provide empirical evidence on the feasibility and the correctness of our proposal.

On energy-based profiling of malware in Android

MERLO, ALESSIO;
2014-01-01

Abstract

The growing spread of malware on Android OS requires new approaches for the detection and recognition of malicious applications on mobile devices. An emerging idea is characterizing malicious behaviors in terms of energy consumption, to support the definition of Energy-aware Intrusion Detection Systems that are able to recognize malicious behaviors in terms of their energy footprint. To this aim, the energy consumption of several hardware components of a mobile device must be measured at a sufficiently fine-grained level of precision. Furthermore, the same measurements must not be energyhungry. In Android, several sources can provide energy consumption information, from high-level API to low level measurements taken directly from the battery driver. In this paper, we consider two approaches to measurements available in literature and, by measuring the consumption of a device under attack, we empirically assess their suitability to support the profiling of both benign and malicious applications in Android. Then, we propose a new approach able to overcome the limitations of the existing ones and we provide empirical evidence on the feasibility and the correctness of our proposal.
2014
9781479953110
Android Security; Malware; Energy-awareness; Measurements;
File in questo prodotto:
File Dimensione Formato  
06903732.pdf

non disponibili

Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 895.5 kB
Formato Adobe PDF
895.5 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14252/1172
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
social impact