Dergiler / Erzincan Üniversitesi Fen Bilimleri Enstitüsü Dergisi / 2021 / Cilt: 14 - Sayı: 1
Hybroid: Benzersiz Hibrit Bir Android Kötücül Yazılım Tespit Uygulama Çatısı
- Sayfa
- 331–356
- DOI
- —
Özet
Dünyanın en çok kullanılan mobil işletim sistemi olan Android, zararsız kullanıcılar gibi kötücül yazılım geliştiricilerin de ilgisini çekmektedir. Android tarafından ön alıcı ciddi eylemler alınmasına rağmen Android kötücül yazılım artan kötücül yazılım çeşitliliği ve karmaşıklığı sebebiyle hala yaygındır. Android kötücül yazılım sistemleri genellikle ikiye ayrılır: (1) Statik analiz ve (2) dinamik analiz. Bu çalışmada statik ve dinamik analizi birleştirerek her ikisinin de avantajlarından faydalanan Hybroid ismiyle benzersiz bir hibrit Android kötücül yazılım tespit uygulama çatısı sunulmuştur. Çalışmada tartışıldığı üzere Android'in yeni sürümlerinde sunulan yeni güvenlik mekanizmalarıyla birlikte problemi güncel bir bakış açısıyla ele almak için Android'in güncel bir sürümü, Android Oreo, kullanılmıştır. Hybroid uygulamadan oluşan geniş bir verisetinde test edilmiş ve Hybroid'in doğruluğu J48 sınıflandırma algoritması kullanıldığında en gelişkin uygulamaları geride bırakarak kadar yüksek çıkmıştır. Deneysel sonuçlar neticesinde elde edilen en önemli bulgular Android kötücül yazılım tespitine ışık tutmak amacıyla tartışılmıştır.
Abstract
Android, the most widely-used mobile operating system, attracts the attention of malware developers as well as benign users. Despite the serious proactive actions taken by Android, the Android malware is still widespread as a result of the increasing sophistication and the diversity of malware. Android malware detection systems are generally classified into two: (1) Static analysis, and (2) dynamic analysis. In this study, a novel Android malware detection framework, namely, Hybroid, was proposed which combines both the static and dynamic analysis techniques to benefit from the advantages of both of these techniques. An up-todate version of Android, namely, Android Oreo, was specifically employed in order to handle the problem from an up-to-date perspective as the recent versions of Android provide new security mechanisms, which are discussed with this study. Hybroid was evaluated on a large dataset that consists of applications, and the accuracy of Hybroid was calculated as high as when it was utilized with the J48 classification algorithm which outperforms the state-of-the-art studies. The key findings in consequence of the experimental result are discussed in order to shed light on Android malware detection.