Title
Characterization of Android Applications with Root Exploit by Using Static Feature Analysis.
Abstract
Recently, more and more rootkit tools are provided by some well-known vendors in the mainstream Android markets. Many people are willing to root their phones to uninstall pre-installed applications, flash third-party ROMs and so on. As it is reported, a significant proportion of Android phones are rooted at least one time. However, applications with root exploit bring critical security threat to users. When the phone is rooted, the permission system, which enforces access control to those privacy-related resources in Android phones, could be bypassed. Thus, the phone will be an easy point for malware to launch attacks. What's more, even the phone is unrooted, permission escalation attacks also can be carried out. Remarkably, an amount of sophisticated Android malware embeds root exploit payloads. Hence, root exploit always suggests high security risk. It is a pressing concern for researchers to characterize and detect applications with root exploit. In this paper, a novel method to extract key features of apps with root exploit is proposed. Contrary to existing works, contrasting the static features between applications with and without root exploit comprehensively are considered at the first time. We complete and evaluate the methodology on two clean apps and two malware dataset, comprising 52, 1859, 463 and 797 applications respectively. Our empirical results suggest the peculiar features can be obtained, which can capture the key differences between applications with and without root exploit to characterize Android root exploit applications.
Year
DOI
Venue
2015
10.1007/978-3-319-27161-3_14
ICA3PP (Workshops and Symposiums)
Keywords
Field
DocType
Android application,Root exploit,Static features,Apriori-based feature comparison,Feature combination,Characterization
Permission,Android (operating system),Computer science,Computer security,Rootkit,Exploit,Phone,Access control,Malware,Operating system,Pattern recognition (psychology)
Conference
Volume
ISSN
Citations 
9532
0302-9743
0
PageRank 
References 
Authors
0.34
7
4
Name
Order
Citations
PageRank
Huikang Hao131.13
Zhoujun Li2121.53
Yueying He3226.71
Jinxin Ma4226.02