R-PackDroid: Practical On-Device Detection of Android Ransomware

05/24/2018
by   Michele Scalas, et al.
0

Ransomware constitutes a major threat for the Android operating system. It can either lock or encrypt the target devices, and victims may be forced to pay ransoms to restore their data. Despite previous works on malware detection, little has been done to specifically identify Android malware as ransomware. This is crucial, as ransomware requires immediate countermeasures to avoid data being entirely compromised. In this paper, we propose R-PackDroid, a machine learning-based application (which directly runs on Android phones) for the detection of Android ransomware. R-PackDroid is a lightweight approach that leverages a methodology based on extracting information from system API packages. We demonstrate its effectiveness by testing it on a wide number of legitimate, malicious and ransomware-based applications. Our analyses pointed out three major results: first, R-PackDroid can distinguish ransomware from malware and legitimate applications with very high accuracy; second, R-PackDroid guarantees resilience against heavy obfuscation attempts, such as class encryption; third, R-PackDroid can be used to effectively predict and detect novel ransomware samples that are released after the ones used to train the system. R-Packdroid is available on the Google Play Store, and it is the first, academic ransomware-oriented detector available for Android.

READ FULL TEXT

page 6

page 8

page 9

page 12

research
01/14/2019

Android Malware Detection Using Autoencoder

Smartphones have become an intrinsic part of human's life. The smartphon...
research
05/11/2022

A Longitudinal Study of Cryptographic API – a Decade of Android Malware

Cryptography has been extensively used in Android applications to guaran...
research
01/30/2023

A Comprehensive Investigation of Feature and Model Importance in Android Malware Detection

The popularity and relative openness of Android means it is a popular ta...
research
10/14/2019

Comment on "AndrODet: An adaptive Android obfuscation detector"

We have identified a methodological problem in the empirical evaluation ...
research
03/09/2018

Explaining Black-box Android Malware Detection

Machine-learning models have been recently used for detecting malicious ...
research
09/06/2019

SEdroid: A Robust Android Malware Detector using Selective Ensemble Learning

For the dramatic increase of Android malware and low efficiency of manua...
research
05/17/2018

DroidMark: A Tool for Android Malware Detection using Taint Analysis and Bayesian Network

With the increasing user base of Android devices and advent of technolog...

Please sign up or login with your details

Forgot password? Click here to reset