| Optimal performance counter events for detecting Android malware | 
| Posted on:2014-11-07 | Degree:M.S.S.E | Type:Thesis | 
| University:The University of Alabama in Huntsville | Candidate:Stinson, Hunter | Full Text:PDF | 
| GTID:2458390008458714 | Subject:Engineering | 
| Abstract/Summary: |  PDF Full Text Request | 
| This work uses salience testing techniques to identify the best performance counter events for detecting malware on Android devices. Modifications were made to a Linux kernel module to enable monitoring and logging of performance counter events. Numerous experiments combining different performance counter events were conducted, and a variety of data aggregation and classification techniques were evaluated. Experiment results were analyzed as to determine how well certain combinations of performance counter events classify applications as malware or non-malware. Results indicate that there are combinations of performance counter events that do much better at detecting malware than those presented in prior work. | 
| Keywords/Search Tags: | Performance counter events, Malware | 
|  PDF Full Text Request | 
| Related items |