A Hybrid Framework for Malware Detection on Smartphones Using ELF Structural & PCB Runtime Traces
Sophisticated mobile computing devices - Tablets and smartphones - escalating their processing and storage capabilities and gaining popularity in the consumer market, but also in the mysterious world of hackers and malware writers. Existing commercial anti-malware products and non-signature-based techniques are unable to detect zero-day, repacked and polymorphic malware with high accuracy, low false-alarm-rate and small detection-overheads. To this end, the authors present a novel hybrid framework which consists of two components: ELF Structural Tracer (EST) and PCB Runtime Tracer (PRT). EST extracts the structural traces of executables to devise a non-signature-based zero-day malware-detection scheme for ARM-Linux on smartphones.