Mmda: Metadata Based Malware Detection on Android

Kun Wang,Tao Song,Alei Liang
DOI: https://doi.org/10.1109/cis.2016.0145
2016-01-01
Abstract:With the development of smart phones, Android, one of the most popular mobile platforms, becomes a vulnerable target. Many malicious applications hide in the android markets, aiming to mislead users to install them unconsciously, and then steal users' personal data, send premium rate SMS messages and gain root privileges of the phones. In this paper, we propose a lightweight method based on applications' metadata for malware detection in android, Mmda. Mmda statically analyzes the apk executable file of an application to get the application's metadata, which includes permissions, hardware features and receiver actions. Next, Mmda constructs a feature space for our dataset, andappliesseveralpopularmachinelearningclassifierstoclassify applications to malware or goodware. In our evaluation with 20023 goodware samples and 20045 malware samples, Random Forest classifier outperforms other classifiers, with a malware detection rate up to 94%. In contrast with popular anti-virus scanners from Virus Total, Mmda with Random Forest has a better detection rate among the most recent dataset.
What problem does this paper attempt to address?