Potential Component Leaks in Android Apps: An Investigation into a New Feature Set for Malware Detection

Li Li,kevin allix,daoyuan li,alexandre bartel,Tegawendé F. Bissyandé,jacques klein
DOI: https://doi.org/10.1109/QRS.2015.36
2015-01-01
Abstract:We discuss the capability of a new feature set for malware detection based on potential component leaks (PCLs). PCLs are defined as sensitive data-flows that involve Android inter-component communications. We show that PCLs are common in Android apps and that malicious applications indeed manipulate significantly more PCLs than benign apps. Then, we evaluate a machine learning-based approach relying on PCLs. Experimental validations show high performance for identifying malware, demonstrating that PCLs can be used for discriminating malicious apps from benign apps.
What problem does this paper attempt to address?