<oai_dc:dc xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
  <dc:contributor>Malek, Miroslaw</dc:contributor>
  <dc:creator>Milošević, Jelena</dc:creator>
  <dc:date>2017-10-30</dc:date>
  <dc:description xmlns:ns0="xml" ns0:lang="en">The number of smart and connected mobile devices is increasing, bringing enormous possibilities to users in various domains and  transforming everything that we get in touch with into smart. Thus, we have smart watches, smart phones, smart homes, and finally even  smart cities. Increased smartness of mobile devices means that they contain more valuable information about their users, more decision  making capabilities, and more control over sometimes even life-critical systems. Although, on one side, all of these are necessary in order to  enable mobile devices maintain their main purpose to help and support people, on the other, it opens new vulnerabilities. Namely, with  increased number and volume of smart devices, also the interest of attackers to abuse them is rising, making their security one of the main  challenges. The main mean that the attackers use in order to abuse mobile devices is malicious software, shortly called malware. One way to  protect against malware is by using static analysis, that investigates the nature of software by analyzing its static features. However, this  technique detects well only known malware and it is prone to obfuscation, which means that it is relatively easy to create a new malicious  sample that would be able to pass the radar. Thus, alone, is not powerful enough to protect the users against increasing malicious attacks. The  other way to cope with malware is through dynamic analysis, where the nature of the software is decided based on its behavior during its  execution on a device. This is a promising solution, because while the code of the software can be easily changed to appear as new, the same  cannot be done with ease with its behavior when being executed. However, in order to achieve high accuracy dynamic analysis usually  requires computational resources that are beyond suitable for battery-operated mobile devices. This is further complicated if, in addition to  detecting the presence of malware, we also want to understand which type of malware it is, in order to trigger suitable countermeasures.  Finally, the decisions on potential infections have to happen early enough, to guarantee minimal exposure to the attacks. Fulfilling these  requirements in a mobile, battery-operated environments is a challenging task, for which, to the best of our knowledge, a suitable solution is  not yet proposed. In this thesis, we pave the way towards such a solution by proposing a dynamic malware detection system that is able to  early detect malware that appears at runtime and that provides useful information to discriminate between diverse types of malware while  taking into account limited resources of mobile devices. On a mobile device we monitor a set of the representative features for presence of  malware and based on them we trigger an alarm if software infection is observed. When this happens, we analyze a set of previously stored  information relevant for malware classification, in order to understand what type of malware is being executed. In order to make the detection  efficient and suitable for resource-constrained environments of mobile devices, we minimize the set of observed system parameters to only the  most informative ones for both detection and classification. Additionally, since sampling period of monitoring infrastructure is directly connected  to the power consumption, we take it into account as an important parameter of the development of the detection system. In order to make  detection effective, we use dynamic features related to memory, CPU, system calls and network as they reflect well the behavior of a system.  Our experiments show that the monitoring with a sampling period of eight seconds gives a good trade-off between detection accuracy,  detection time and consumed power. Using it and by monitoring a set of only seven dynamic features (six related to the behavior of memory  and one of CPU), we are able to provide a detection solution that satisfies the initial requirements and to detect malware at runtime with F- measure of 0.85, within 85.52 seconds of its execution, and with consumed average power of 20mW. Apart from observed features containing  enough information to discriminate between malicious and benign applications, our results show that they can also be used to discriminate  between diverse behavior of malware, reflected in different malware families. Using small number of features we are able to identify the  presence of the malicious records from the considered family with precision of up to 99.8%. In addition to the standalone use of the proposed  detection solution, we have also used it in a hybrid scenario where the applications were first analyzed by a static method, and it was able to  detect correctly all the malware previously undetected by static analysis with false positive rate of 3.81% and average detection time of 44.72s.  The method, we have designed, tested and validated, has been applied on a smartphone running on Android Operating System. However,  since in the design of this method efficient usage of available computational resources was one of our main criteria, we are confident that the  method as such can be applied also on the other battery-operated mobile devices of Internet of Things, in order to provide an effective and  efficient system able to counter the ever-increasing and ever-evolving number and a variety of malicious attacks.</dc:description>
  <dc:format>application/pdf</dc:format>
  <dc:identifier>https://susi.usi.ch/global/documents/318616</dc:identifier>
  <dc:identifier>https://n2t.net/ark:/12658/srd1318616</dc:identifier>
  <dc:identifier>https://susi.usi.ch/documents/318616/files/2017INFO012.pdf</dc:identifier>
  <dc:language>eng</dc:language>
  <dc:relation>info:eu-repo/semantics/altIdentifier/urn/urn:nbn:ch:rero-006-116826</dc:relation>
  <dc:relation>info:eu-repo/semantics/altIdentifier/ark/12658/srd1318616</dc:relation>
  <dc:rights>info:eu-repo/semantics/openAccess</dc:rights>
  <dc:rights>License undefined</dc:rights>
  <dc:subject xmlns:ns1="xml" ns1:lang="en">Malware</dc:subject>
  <dc:subject xmlns:ns2="xml" ns2:lang="en">Malware detection</dc:subject>
  <dc:subject xmlns:ns3="xml" ns3:lang="en">Dynamic detection</dc:subject>
  <dc:subject xmlns:ns4="xml" ns4:lang="en">Security</dc:subject>
  <dc:subject xmlns:ns5="xml" ns5:lang="en">Resource-constrained devices</dc:subject>
  <dc:subject xmlns:ns6="xml" ns6:lang="en">Mobile devices</dc:subject>
  <dc:subject xmlns:ns7="xml" ns7:lang="en">Android</dc:subject>
  <dc:subject xmlns:ns8="xml" ns8:lang="en">Feature selection</dc:subject>
  <dc:subject xmlns:ns9="xml" ns9:lang="en">Early detection</dc:subject>
  <dc:subject>info:eu-repo/classification/udc/004</dc:subject>
  <dc:title xmlns:ns10="xml" ns10:lang="en">Malware detection at runtime for resource-constrained mobile devices : data-driven approach</dc:title>
  <dc:type>http://purl.org/coar/resource_type/c_db06</dc:type>
</oai_dc:dc>
