ApkClassiFy: Identification and Classification of Packed Android Malicious Applications.

Xu Guo,Tao Zheng,Xingshu Chen,Qixu Wang,Jiang Shao,Zhijie Hu
DOI: https://doi.org/10.1109/globecom48099.2022.10001463
2022-01-01
Abstract:There are becoming increasingly common for Android malware with packer protection, which can effectively evade malware detection. Thus the packed identification is very required. However, current packers identification schemes cannot efficiently deal with mixed packers and fail to provide a suitable unpacking scheme. In this paper, we propose a new method called ApkClassiFy. By constructing a fingerprint feature library and classification mapping library, ApkClassiFy can accurately identify and classify Android-packed malware, effectively identifying mixed packing applications and providing a corresponding unpacking scheme. To further verify the performance of ApkClassiFy, we constructed the Android malware dataset MalApk and the packed Android malware classification dataset OmixShell. The experimental results show ApkClassiFy has higher accuracy and lower false positives in detecting packed Android malware than other packed identification schemes. Besides, ApkClassiFy can also classify packers to identify mixed packers and help analysts choose the appropriate unpacking scheme.
What problem does this paper attempt to address?