Optimal performance counter events for detecting Android malware |
Posted on:2014-11-07 | Degree:M.S.S.E | Type:Thesis |
University:The University of Alabama in Huntsville | Candidate:Stinson, Hunter | Full Text:PDF |
GTID:2458390008458714 | Subject:Engineering |
Abstract/Summary: | |
This work uses salience testing techniques to identify the best performance counter events for detecting malware on Android devices. Modifications were made to a Linux kernel module to enable monitoring and logging of performance counter events. Numerous experiments combining different performance counter events were conducted, and a variety of data aggregation and classification techniques were evaluated. Experiment results were analyzed as to determine how well certain combinations of performance counter events classify applications as malware or non-malware. Results indicate that there are combinations of performance counter events that do much better at detecting malware than those presented in prior work. |
Keywords/Search Tags: | Performance counter events, Malware |
|
Related items |