A smartphone is a mobile phone that provides advanced functions compared to traditional mobile phones. Smartphone systems have evolved considerably in terms of their capacity and functionality. Therefore, it is excessively used in personal and business life. Users of smartphone systems store all kinds of personal, business and confidential information on their systems, such as credit card and bank account information. In view of this popularity and storing confidential information, the cyber criminals and malware developers have set their eyes on the smartphone systems. Recent malware analysis reports show scared information about the serious threats that face smartphone systems. Thus, their protection is very important.
Smartphone malwares detection techniques have been actively studied. Broadly, the two main techniques are: the signature-based techniques and the anomaly-based techniques. Each technique has its own advantages and drawbacks. In this Thesis, we are mainly interested in anomaly detection techniques. These techniques are useful for unknown malwares and variants of known ones. However, they still need more study and investigation to improve the malware detection accuracy and to consume as less resources as possible.
This Thesis makes contributions on three levels to improve the efficiency, accuracy and adaptability of anomaly-based techniques for smartphone system based on Android operating system.
The first contribution presents a study and review of the existing malware detection techniques. This survey provides a comprehensive classification of the studied techniques according to well defined criteria.
The second contribution is based upon the dataset level and it is twofold. Firstly, we introduce dataset feature vector representation as a new factor that can improve the efficiency and the accuracy of malware detection solution. Secondly, we introduce filtering and abstraction process that refines the system call traces. The refined traces are much more compact and are closer to the main application behavior.
The third contribution of this Thesis is on the benign behavior model level and it is biflod. In the first place, we build canonical database representing generic benign behavior from limited number of representative applications. In the second place, instead of using single machine learning classifier to model the benign behavior, we use hybrid machine learning classifier.
| Date | 21 mai 2015 |
|---|
| langue originale | Français |
|---|
| Établissement diplômant | - École de technologie supérieure
|
|---|
| Superviseur | Jean-Marc Robert (Directeur(-trice)) & Talhi Chamseddine (Codirecteur(-trice)) |
|---|
- Détection d'anomalies (Sécurité informatique) Logiciels malveillants Prévention. Téléphones intelligents Sécurité Mesures. Systèmes de classeurs. appel
- système
- filtrage et abstraction
- classificateur d’apprentissage automatique
- Android
Amamra, A. (Auteur(e)),
Robert (Directeur(-trice)) & Chamseddine (Codirecteur(-trice)),
21 mai 2015Thèses et mémoires: Thèse de doctorat › Doctorat en génie: Génie