Several solutions ensuring the dynamic detection of malicious activities on Android ecosystem have been proposed. These are represented by generic rules and models that identify any purported malicious behavior. However, the approaches adopted are far from being effective in detecting malware (listed or not) and whose form and behavior are likely to be different depending on the execution environment or the design of the malware itself (polymorphic for example). An additional difficulty is added when these approaches are unable to capture, analyze, and classify all the execution paths incorporated in the analyzed application earlier. This suggests that the functionality of the analyzed application can constitute a potential risk but never explored or revealed. We have studied some malware detection techniques based on behavioral analysis of applications. The description, characteristics, and results obtained from each technique are presented in this article wherein we have also highlighted some open problems, challenges as well as the different possible future directions of research concerning behavioral analysis of malware.
翻译:针对Android生态系统中恶意活动的动态检测,已有多种解决方案被提出。这些方案通过通用规则和模型来识别任何所谓的恶意行为。然而,现有方法在检测恶意软件(无论是已知还是未知的)方面远非有效,且这些恶意软件的形式和行为可能因执行环境或恶意软件本身的设计(例如多态性)而有所不同。当这些方法无法捕捉、分析和分类被分析应用中包含的所有执行路径时,额外的困难随之产生。这表明被分析应用的功能可能构成潜在风险,但从未被探索或揭示。我们研究了一些基于应用行为分析的恶意软件检测技术。本文介绍了每种技术的描述、特征和结果,并突出了与恶意软件行为分析相关的一些开放问题、挑战以及未来可能的研究方向。