SysDroid: Maximizing Android Malware Detection via SAILS and Dynamic System Call Analysis

SysDroid: a dynamic ML-based android malware analyzer using system call traces

2020-01-13
A. Ananya, A. Aswathy, T. R. Amal, P. G. Swathy, Vinod P, Mohammad Shojafar
Summary
Problem
Method
Results
Takeaways
Abstract

SysDroid is a dynamic Android malware analyzer that utilizes Linux system call traces and N-gram features to distinguish malicious applications from benign ones. The core contribution is "SAILS," a novel feature selection mechanism that improves upon classical selectors (MI, GSS, DFS) to identify the most discriminative system calls, achieving detection accuracies between 95% and 99.4%.

TL;DR

SysDroid is a dynamic analysis framework that leverages system call traces to identify Android malware. By introducing SAILS, a specialized feature selection algorithm, and testing across N-gram sequences, the authors achieved near-perfect accuracy (up to 99.4%). However, the work serves as a double-edged sword, demonstrating that even SOTA classifiers are highly vulnerable to evasion through adversarial benign-feature injection.

The Dynamic Analysis Imperative

As malware authors increasingly adopt encryption and packing, static analysis—once the bedrock of mobile security—has become insufficient. The industry has shifted toward Dynamic Analysis, observing application behavior at runtime. SysDroid focuses on the "language of the kernel": System Calls. Unlike permissions or API calls, system calls are essential for interaction with OS resources (e.g., read, socket, ioctl), making them harder to hide.

Methodology: The SAILS Algorithm

The researchers identified that simply collecting system calls results in a "noisy" feature space. To solve this, they developed SAILS (Selection of relevant Attributes for Improving Locally extracted features).

How SAILS Works:

  1. Local Scoring: Classical selectors like Mutual Information (MI) and Distinguishing Feature Selector (DFS) calculate scores for system calls relative to Malware and Benign classes.
  2. Dual Max-Heaps: System calls are organized into two heaps (Malware and Benign) based on these scores.
  3. Prominence Ranking: The algorithm iteratively selects the most discriminative calls from both tops, ensuring the final feature set is balanced and highly representative of both malicious patterns and legitimate behaviors.

System Architecture Figure 1: The SysDroid Workflow - From Data Collection via Android Monkey to Feature Vector Generation.

Experiments and Results

The authors tested five major ML/DL models: Logistic Regression (LR), CART, Random Forest (RF), XGBoost, and Deep Neural Networks (DNN).

  • N-gram Efficacy: Moving from Unigrams to Bigrams/Trigrams significantly improved performance. Trigrams, in particular, provided the contextual sequence necessary to identify malicious behavior chains.
  • The Winner: XGBoost with bigrams reached 99.4% accuracy, while Logistic Regression proved more resilient in the massive feature space of trigrams.
  • DNN Insights: The study found that dropout rates between 0.1–0.8 and specific learning rates were critical to prevent the local minima traps common in malware datasets.

Performance Data Table 1: Accuracy comparison across different classifiers and N-gram levels using SAILS-enhanced features.

The Achilles' Heel: Adversarial Evasion

The most striking section of the paper is the evaluation of Adversarial Machine Learning (AML). The authors simulated an "Evasion Attack" where a hacker appends a small percentage of benign system calls to a malware sample.

The impact was devastating:

  • For CART, the recall rate crashed from 96.55% to 33.73% with just a 1% injection of benign calls.
  • XGBoost remained more robust than others but still saw a decline.

This "Blind Spot" exists because the models learn that certain benign calls are strong indicators of safety. By artificially inflating these indicators, malware can "mask" its identity without changing its underlying malicious payload.

Critical Insight & Future Outlook

SysDroid highlights a critical paradox in AI-driven security: the more precisely we tune a feature selector to "relevant" attributes, the more we define a specific "shape" for the attacker to avoid.

Takeaways for the Industry:

  1. Dynamic is Better, but Not Bulletproof: System calls provide deep visibility, but they are still susceptible to behavioral camouflaging.
  2. Adversarial Training is Mandatory: Future models cannot just be trained on "clean" data; they must be trained on perturbed samples to stay relevant.
  3. Hybridization: Future work should combine system call sequences with network traffic and IPC (Inter-Process Communication) patterns to increase the "cost of evasion" for attackers.

Conclusion

SysDroid successfully proves that SAILS-driven feature selection can push detection accuracy to the limit. However, its security evaluation serves as a warning: in the cat-and-mouse game of Android security, accuracy is nothing without robustness.

Find Similar Papers

Try Our Examples

  • Search for recent papers on adversarial training techniques specifically designed to defend Android malware classifiers against system call injection attacks.
  • Which original studies established the effectiveness of system call N-grams in malware detection, and how does the SAILS method specifically advance those ranking algorithms?
  • Investigate how the SysDroid methodology could be extended to analyze network traffic patterns or hardware-level intents in conjunction with system calls for a multi-modal hybrid defense.
Contents
SysDroid: Maximizing Android Malware Detection via SAILS and Dynamic System Call Analysis
1. TL;DR
2. The Dynamic Analysis Imperative
3. Methodology: The SAILS Algorithm
3.1. How SAILS Works:
4. Experiments and Results
5. The Achilles' Heel: Adversarial Evasion
6. Critical Insight & Future Outlook
7. Conclusion