Research Article

KTSDroid: A Framework for Android Malware Categorization Using the Kernel Task Structure

Table 8

Selected features using mutual information (MI).

RepFeature nameMI score

M_F1task -> mm -> mmap -> vm_file -> f_inode -> i_generation1.51
M_F2task -> mm -> mmap_base1.50
M_F3task -> mm -> brk1.50
M_F4task -> mm -> mmap_legacy_base1.49
M_F5task -> mm -> start_brk1.49
M_F6task -> mm -> end_data1.49
M_F7task -> mm -> start_code1.49
M_F8task -> mm -> start_data1.49
M_F9task -> mm -> end_code1.48
M_F10task -> mm -> mmap -> vm_file -> f_inode -> i_ino1.43
M_F11task -> mm -> shared_vm0.74
M_F12task -> mm -> total_vm0.64
M_F13task -> mm -> hiwater_vm0.59
M_F14task -> mm -> exec_vm0.47
M_F15task -> mm -> env_end0.43
M_F16task -> mm -> start_stack0.43
M_F17task -> mm -> arg_end0.42
M_F18task -> mm -> arg_start0.42
M_F19task -> mm -> env_start0.42
M_F20task -> mm -> highest_vm_end0.41
M_F21task -> mm -> mm_count -> counter0.41
P_F1task -> cred -> session_keyring -> last_used_at1.51
P_F2task -> real_cred -> session_keyring -> last_used_at1.51
P_F3task -> real_cred -> session_keyring -> serial1.50
P_F4task -> cred -> session_keyring -> serial1.50
S_F1task -> sas_ss_sp1.49
S_F2task -> signal -> ioac -> rchar0.60
S_F3task -> signal -> ioac -> wchar0.46
S_F4task -> signal -> real_timer -> base -> cpu_base -> clock_was_set_seq0.38