An important attack vector targeting Android Smartphone is repackaging legitimate applications to inject malicious activities. This kind of attack can be detected mainly by monitoring the behavior of applications for potential deviations. However, running this detection approach on a mobile environment is not straightforward due to resource constraints imposed by smartphones.
This thesis focuses on the usability of on-device anomaly detection algorithms on small-scale embedded systems and proposes a lightweight detection framework for Android-based devices that handles the trade-offs between detection accuracy and resource consumption. The proposed solution allows for the local and remote construction of normal behavior based on various anomaly detection algorithms applied to system calls traces. In our experiments, we applied the proposed anomaly detection model to real and self-written malware samples of three different legitimate mobile applications.
The results shows that our on-device detection framework is able to achieve a good compromise between security and usability without relying on a remote server.
| Date | 23 Jul 2015 |
|---|
| Original language | French |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Chamseddine Talhi (Supervisor) & Wahab Hamou-Lhadj (Co-supervisor) |
|---|
Ben Attia, M. (Author),
Talhi (Supervisor) & Hamou-Lhadj (Co-supervisor),
23 Jul 2015Student thesis: Master's thesis › Master in Engineering: Information Technology Engineering