DroidClone: Attack of the Android Malware Clones - A Step Towards Stopping Them

dc.authoridAlam, Shahid/0000-0002-4080-8042
dc.contributor.authorAlam, Shahid
dc.contributor.authorSogukpinar, Ibrahim
dc.date.accessioned2025-01-06T17:36:21Z
dc.date.available2025-01-06T17:36:21Z
dc.date.issued2021
dc.description.abstractCode clones are frequent in use because they can be created fast with little effort and expense. Especially for malware writers, it is easier to create a clone of the original than writing a new malware. According to the recent Symantec threat reports, Android continues to be the most targeted mobile platform, and the number of new mobile malware clones grew by 54%. There is a need to develop techniques and tools to stop this attack of Android malware clones. To stop this attack, we propose DroidClone that exposes code clones (segments of code that are similar) in Android applications to help detect malware. DroidClone is the first such effort uses specific control flow patterns for reducing the effect of obfuscations and detect clones that are syntactically different but semantically similar up to a threshold. DroidClone is independent of the programming language of the code clones. When evaluated with real malware and benign Android applications, DroidClone obtained a detection rate of 94.2% and false positive rate of 5.6%. DroidClone, when tested against various obfuscations, was able to successfully provide resistance against all the trivial (Renaming methods, parameters, and nop insertion, etc) and some non-trivial (Call graph manipulation and function indirection, etc.) obfuscations.
dc.identifier.doi10.2298/CSIS200330035A
dc.identifier.endpage91
dc.identifier.issn1820-0214
dc.identifier.issue1
dc.identifier.scopus2-s2.0-85100526648
dc.identifier.scopusqualityQ3
dc.identifier.startpage67
dc.identifier.urihttps://doi.org/10.2298/CSIS200330035A
dc.identifier.urihttps://hdl.handle.net/20.500.14669/1829
dc.identifier.volume18
dc.identifier.wosWOS:000614630200005
dc.identifier.wosqualityQ4
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherComsis Consortium
dc.relation.ispartofComputer Science and Information Systems
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_20241211
dc.subjectAndroid
dc.subjectCode Clones
dc.subjectMAIL
dc.subjectMalware Analysis and Detection
dc.subjectTF-IDF
dc.subjectMachine Learning
dc.titleDroidClone: Attack of the Android Malware Clones - A Step Towards Stopping Them
dc.typeArticle

Dosyalar