Research Article

KTSDroid: A Framework for Android Malware Categorization Using the Kernel Task Structure

Table 10

Final feature set used by KTSDroid.

RepFeature nameDepth

M_F1task -> mm -> mmap -> vm_file -> f_inode -> i_generation6
M_F2task -> mm -> mmap_legacy_base3
M_F3task -> mm -> end_data4
M_F4task -> mm -> mmap_base3
M_F10task -> mm -> mmap -> vm_file -> f_inode -> i_ino6
M_F11task -> mm -> shared_vm3
M_F12task -> mm -> total_vm3
M_F14task -> mm -> exec_vm3
M_F20task -> mm -> mm_count -> counter4
P_F1task -> real_cred -> session_keyring -> last_used_at4
P_F3task -> real_cred -> session_keyring -> serial4
S_F1task -> sas_ss_sp2
S_F2task -> signal -> ioac -> rchar4
S_F3task -> signal -> ioac -> wchar4