RiskRanker: scalable and accurate zero-day android malware detection

  • Authors:
  • Michael Grace;Yajin Zhou;Qiang Zhang;Shihong Zou;Xuxian Jiang

  • Affiliations:
  • North Carolina State University, Raleigh, NC, USA & NQ Mobile Security Research Center, Beijing, China;North Carolina State University, Raleigh, NC, USA;NQ Mobile Security Research Center, Beijing, China;NQ Mobile Security Research Center, Beijing, China;North Carolina State University, Raleigh, NC, USA & NQ Mobile Security Research Center, Beijing, China

  • Venue:
  • Proceedings of the 10th international conference on Mobile systems, applications, and services
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Smartphone sales have recently experienced explosive growth. Their popularity also encourages malware authors to penetrate various mobile marketplaces with malicious applications (or apps). These malicious apps hide in the sheer number of other normal apps, which makes their detection challenging. Existing mobile anti-virus software are inadequate in their reactive nature by relying on known malware samples for signature extraction. In this paper, we propose a proactive scheme to spot zero-day Android malware. Without relying on malware samples and their signatures, our scheme is motivated to assess potential security risks posed by these untrusted apps. Specifically, we have developed an automated system called RiskRanker to scalably analyze whether a particular app exhibits dangerous behavior (e.g., launching a root exploit or sending background SMS messages). The output is then used to produce a prioritized list of reduced apps that merit further investigation. When applied to examine 118,318 total apps collected from various Android markets over September and October 2011, our system takes less than four days to process all of them and effectively reports 3281 risky apps. Among these reported apps, we successfully uncovered 718 malware samples (in 29 families) and 322 of them are zero-day (in 11 families). These results demonstrate the efficacy and scalability of RiskRanker to police Android markets of all stripes.