
402
Big Data: Storage, Sharing, and Security
Extract statistically
improbable
features
Normalize
features in bloom
filter
Signature generation
with statistically
improbable features
Malicious app/
signature match
percentage with
known malicious
app and family
Repackaged app
from known family
Malware app
signatures DB
Match
Google Play apps
ird-party
market apps
Obfuscated
malware apps
Android application
package
(APK)
Manifest.xml
Classes_dex
resources
Alert
Figure 17.2: AndroSimilar methodology. (Data from Faruki, P. et al., AndroSimilar: Robust
statistical feature signature for Android malware detection, Presented at the Proceedings of
the 6th International Conference on ...