25
VIRUSMETER: PREVENTING YOUR CELLPHONE FROM SPIES RAID 2009 Lei Liu, Department of Computer Science, George Mason University Guanhua Yan, Information Sciences Group, Los Alamos National Laboratory Xinwen Zhang, Computer Science Lab, Samsung Information Systems America Songqing Chen, Department of Computer Science, George Mason University

VirusMeter : Preventing Your Cellphone from Spies RAID 2009

  • Upload
    garson

  • View
    45

  • Download
    0

Embed Size (px)

DESCRIPTION

Lei Liu, Department of Computer Science, George Mason University Guanhua Yan, Information Sciences Group, Los Alamos National Laboratory Xinwen Zhang, Computer Science Lab, Samsung Information Systems America Songqing Chen, Department of Computer Science, George Mason University. - PowerPoint PPT Presentation

Citation preview

Page 1: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009

VIRUSMETER: PREVENTING YOUR CELLPHONE FROM SPIESRAID 2009

Lei Liu, Department of Computer Science, George Mason UniversityGuanhua Yan, Information Sciences Group, Los Alamos National LaboratoryXinwen Zhang, Computer Science Lab, Samsung Information Systems AmericaSongqing Chen, Department of Computer Science, George Mason University

Page 2: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009

Outline

Introduction Related Work Overview

Page 3: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009

Introduction

1 billion camera phones to be shipped in 2008 Smartphones: about 10%, 100 million

units By the end of 2007, over 370

different mobile malware Information stealing, overcharging,

battery exhaustion, network congestion

Page 4: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009

Introduction

Signature-based Encryption, obfuscation, packing

Anomaly-based High false alarm rate

Behavioral signatures Resource-constrained FlexiSPY-like malware doesn’t show

anomalies in the order of relevant API calls

Page 5: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009

Introduction

VirusMeter Based on battery power

Challenges Require power model Need to measure battery power in real-

time Lightweight. Cannot consume too much

CPU and power

Page 6: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009

Related Work

Infection vectors Bluetooth, MMS, memory cards, user

downloading Epidemic spreading in mobile, 2005

ACM WiSe Use user interaction to identify

vulnerable users, 2006 ACM WiSe Behavioral signatures for mobile mal

ware detection, 2008 Mobisys

Page 7: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009

Related Work

Limit Targeting particular situations (e.g.,

attack through MMS) Demand significant infrastructure

support Demand non-trivial computing resoures

from mobile devices

Page 8: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009

Overview

Page 9: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 10: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 11: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 12: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 13: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 14: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 15: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 16: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 17: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 18: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 19: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 20: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 21: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 22: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 23: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 24: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009
Page 25: VirusMeter : Preventing Your  Cellphone  from Spies RAID 2009