Function-oriented mobile malware analysis as first aid

Jae Wook Jang, Huy Kang Kim

Research output: Contribution to journalArticlepeer-review

5 Citations (Scopus)


Recently, highly well-crafted mobile malware has arisen as mobile devices manage highly valuable and sensitive information. Currently, it is impossible to detect and prevent all malware because the amount of new malware continues to increase exponentially; malware detection methods need to improve in order to respond quickly and effectively to malware. For the quick response, revealing the main purpose or functions of captured malware is important; however, only few recent works have attempted to find malware's main purpose. Our approach is designed to help with efficient and effective incident responses or countermeasure development by analyzing the main functions of malicious behavior. In this paper, we propose a novel method for function-oriented malware analysis approach based on analysis of suspicious API call patterns. Instead of extracting API call patterns for malware in each family, we focus on extracting such patterns for certain malicious functionalities. Our proposed method dumps memory sections where an application is allocated and extracts suspicious API sequences from bytecode by comparing with predefined suspicious API lists. By matching API call patterns with our functionality database, our method determines whether they are malicious. The experiment results demonstrate that our method performs well in detecting malware with high accuracy.

Original languageEnglish
Article number6707524
JournalMobile Information Systems
Publication statusPublished - 2016

ASJC Scopus subject areas

  • Computer Science Applications
  • Computer Networks and Communications


Dive into the research topics of 'Function-oriented mobile malware analysis as first aid'. Together they form a unique fingerprint.

Cite this