Third Line of Defense Strategy to Fight against SMS-based Malware in Android Smartphones

Conference Paper
Derhab, Abdelouahid . 2014
Publication Work Type: 
Ph.D.
Conference Name: 
The International Wireless Communications and Mobile Computing Conference (IWCMC 2014)
Conference Location: 
Nicosia, Cyprus
Conference Date: 
Monday, August 4, 2014
Sponsoring Organization: 
IEEE
Publication Abstract: 

In this paper, we inspire from two analogies: the warfare kill zone and the airport check-in system, to design and deploy a new line in the defense-in-depth strategy, called the third line. This line is represented by a security framework, named the Intrusion Ambushing System and is designed to tackle the issue of SMS-based malware in the Android-based Smartphones. The framework exploits the security features offered by Android operating system to prevent the malicious SMS from going out of the phone and detect the corresponding SMS-based malware. We show that the proposed framework can ensure full security against SMS-based malware. In addition, an analytical study demonstrates that the framework offers optimal performance in terms of detection time and execution cost in comparison to intrusion detection systems based on static and dynamic analysis.