{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,31]],"date-time":"2026-03-31T21:32:41Z","timestamp":1774992761126,"version":"3.50.1"},"reference-count":35,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2022,5,26]],"date-time":"2022-05-26T00:00:00Z","timestamp":1653523200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Science Foundation","award":["1938130-CNS"],"award-info":[{"award-number":["1938130-CNS"]}]},{"name":"National Science Foundation","award":["1928349-CNS"],"award-info":[{"award-number":["1928349-CNS"]}]},{"name":"National Science Foundation","award":["2043022-DGE"],"award-info":[{"award-number":["2043022-DGE"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Combating the OS-level malware is a very challenging problem as this type of malware can compromise the operating system, obtaining the kernel privilege and subverting almost all the existing anti-malware tools. This work aims to address this problem in the context of mobile devices. As real-world malware is very heterogeneous, we narrow down the scope of our work by especially focusing on a special type of OS-level malware that always corrupts user data. We have designed mobiDOM, the first framework that can combat the OS-level data corruption malware for mobile computing devices. Our mobiDOM contains two components, a malware detector and a data repairer. The malware detector can securely and timely detect the presence of OS-level malware by fully utilizing the existing hardware features of a mobile device, namely, flash memory and Arm TrustZone. Specifically, we integrate the malware detection into the flash translation layer (FTL), a firmware layer embedded into the flash storage hardware, which is inaccessible to the OS; in addition, we run a trusted application in the Arm TrustZone secure world, which acts as a user-level manager of the malware detector. The FTL-based malware detection and the TrustZone-based manager can communicate with each other stealthily via steganography. The data repairer can allow restoring the external storage to a healthy historical state by taking advantage of the out-of-place-update feature of flash memory and our malware-aware garbage collection in the FTL. Security analysis and experimental evaluation on a real-world testbed confirm the effectiveness of mobiDOM.<\/jats:p>","DOI":"10.3390\/jcp2020017","type":"journal-article","created":{"date-parts":[[2022,5,27]],"date-time":"2022-05-27T07:05:07Z","timestamp":1653635107000},"page":"311-328","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Defending against OS-Level Malware in Mobile Devices via Real-Time Malware Detection and Storage Restoration"],"prefix":"10.3390","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9173-156X","authenticated-orcid":false,"given":"Niusen","family":"Chen","sequence":"first","affiliation":[{"name":"Department of Computer Science, Michigan Technological University, Houghton, MI 49931, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9372-9607","authenticated-orcid":false,"given":"Bo","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Michigan Technological University, Houghton, MI 49931, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,5,26]]},"reference":[{"key":"ref_1","unstructured":"Statista (2022, May 20). Development of New Android Malware Worldwide from June 2016 to March 2020. Available online: https:\/\/www.statista.com\/statistics\/680705\/global-android-malware-volume\/."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Subedi, K.P., Budhathoki, D.R., Chen, B., and Dasgupta, D. (December, January 27). RDS3: Ransomware Defense Strategy by Using Stealthily Spare Space. Proceedings of the 2017 IEEE Symposium Series on Computational Intelligence (SSCI), Honolulu, HI, USA.","DOI":"10.1109\/SSCI.2017.8280842"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Aafer, Y., Du, W., and Yin, H. (2013, January 25\u201328). Droidapiminer: Mining api-level features for robust malware detection in android. Proceedings of the International Conference on Security and Privacy in Communication Systems, Sydney, NSW, Australia.","DOI":"10.1007\/978-3-319-04283-1_6"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Zhang, M., Duan, Y., Yin, H., and Zhao, Z. (2014, January 3\u20137). Semantics-aware android malware classification using weighted contextual api dependency graphs. Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, Scottsdale, AZ, USA.","DOI":"10.1145\/2660267.2660359"},{"key":"ref_5","unstructured":"Kharraz, A., Arshad, S., Mulliner, C., Robertson, W., and Kirda, E. (2016, January 10\u201312). UNVEIL: A Large-Scale, Automated Approach to Detecting Ransomware. Proceedings of the 25th USENIX Security Symposium (USENIX Security 16), Austin, TX, USA."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Kharraz, A., Robertson, W., Balzarotti, D., Bilge, L., and Kirda, E. (2015, January 9\u201310). Cutting the gordian knot: A look under the hood of ransomware attacks. Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Milan, Italy.","DOI":"10.1007\/978-3-319-20550-2_1"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Scaife, N., Carter, H., Traynor, P., and Butler, K.R. (2016, January 27\u201330). Cryptolock (and drop it): Stopping ransomware attacks on user data. Proceedings of the 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS), Nara, Japan.","DOI":"10.1109\/ICDCS.2016.46"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Continella, A., Guagnelli, A., Zingaro, G., De Pasquale, G., Barenghi, A., Zanero, S., and Maggi, F. (2016, January 5\u20138). ShieldFS: A self-healing, ransomware-aware filesystem. Proceedings of the 32nd Annual Conference on Computer Security Applications, Angeles, CA, USA.","DOI":"10.1145\/2991079.2991110"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Guan, L., Jia, S., Chen, B., Zhang, F., Luo, B., Lin, J., Liu, P., Xing, X., and Xia, L. (2017, January 4\u20137). Supporting Transparent Snapshot for Bare-metal Malware Analysis on Mobile Devices. Proceedings of the 33rd Annual Computer Security Applications Conference, Orlando, FL, USA.","DOI":"10.1145\/3134600.3134647"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Chen, N., Xie, W., and Chen, B. (2021, January 21\u201324). Combating the OS-Level Malware in Mobile Devices by Leveraging Isolation and Steganography. Proceedings of the Applied Cryptography and Network Security Workshops, Kanagawa, Japan.","DOI":"10.1007\/978-3-030-81645-2_23"},{"key":"ref_11","unstructured":"(2022, May 20). Open Portable Trusted Execution Environment. Available online: https:\/\/www.op-tee.org\/."},{"key":"ref_12","unstructured":"Xie, W., Chen, N., and Chen, B. (2020, January 18\u201320). Poster: Incorporating Malware Detection into Flash Translation Layer. Proceedings of the 2020 IEEE Symposium on Security and Privacy Poster Session, Virtual."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1883","DOI":"10.4249\/scholarpedia.1883","article-title":"K-nearest neighbor","volume":"4","author":"Peterson","year":"2009","journal-title":"Scholarpedia"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"M\u00fcller, M. (2007). Dynamic time warping. Inf. Retr. Music Motion, 69\u201384.","DOI":"10.1007\/978-3-540-74048-3_4"},{"key":"ref_15","unstructured":"(2022, May 20). Remove(3)\u2014Linux Man Page. Available online: https:\/\/linux.die.net\/man\/3\/remove."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"837","DOI":"10.1145\/1027794.1027801","article-title":"Real-time garbage collection for flash-memory storage systems of real-time embedded systems","volume":"3","author":"Chang","year":"2004","journal-title":"ACM Trans. Embed. Comput. Syst."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1172","DOI":"10.1016\/j.peva.2010.07.003","article-title":"Performance of greedy garbage collection in flash-based solid-state drives","volume":"67","author":"Bux","year":"2010","journal-title":"Perform. Eval."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Bukasa, S.K., Lashermes, R., Le Bouder, H., Lanet, J.L., and Legay, A. (2017, January 28\u201329). How TrustZone could be bypassed: Side-channel attacks on a modern system-on-chip. Proceedings of the IFIP International Conference on Information Security Theory and Practice, Heraklion, Greece.","DOI":"10.1007\/978-3-319-93524-9_6"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Ryan, K. (2019, January 11\u201315). Hardware-backed heist: Extracting ECDSA keys from Qualcomm\u2019s TrustZone. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, London, UK.","DOI":"10.1145\/3319535.3354197"},{"key":"ref_20","unstructured":"Tang, A., Sethumadhavan, S., and Stolfo, S. (2017, January 16\u201318). CLKSCREW: Exposing the perils of security-oblivious energy management. Proceedings of the 26th USENIX Security Symposium (USENIX Security 17), Vancouver, BC, Canada."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Qiu, P., Wang, D., Lyu, Y., and Qu, G. (2019, January 11\u201315). Voltjockey: Breaching trustzone by software-controlled voltage manipulation over multi-core frequencies. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, London, UK.","DOI":"10.1145\/3319535.3354201"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Wan, S., Sun, M., Sun, K., Zhang, N., and He, X. (2020, January 7\u201311). RusTEE: Developing Memory-Safe ARM TrustZone Applications. Proceedings of the Annual Computer Security Applications Conference, Austin, TX, USA.","DOI":"10.1145\/3427228.3427262"},{"key":"ref_23","unstructured":"Zhu, M., and Gupta, S. (2017). To prune, or not to prune: Exploring the efficacy of pruning for model compression. arXiv."},{"key":"ref_24","unstructured":"(2022, May 20). Raspberry Pi 3 Model B. Available online: https:\/\/www.raspberrypi.org\/products\/raspberry-pi-3-model-b\/."},{"key":"ref_25","unstructured":"Mantech (2019, May 17). LPC-H3131. Available online: https:\/\/www.olimex.com\/Products\/ARM\/NXP\/LPC-H3131\/."},{"key":"ref_26","unstructured":"Tankasala, D., Chen, N., and Chen, B. (2022, May 20). A Step-by-step Guideline for Creating A Testbed for Flash Memory Research via LPC-H3131 and OpenNFM. Available online: https:\/\/snp.cs.mtu.edu\/research\/common\/flash-memory-testbed.pdf."},{"key":"ref_27","unstructured":"Code, G. (2019, May 17). OpenNFM. Available online: https:\/\/code.google.com\/p\/opennfm\/."},{"key":"ref_28","unstructured":"(2019, May 17). VirusTotal. Available online: https:\/\/www.virustotal.com\/."},{"key":"ref_29","unstructured":"(2022, May 20). Malware I\/O Traces On Nand flash (MITON) V0.2. Available online: https:\/\/snp.cs.mtu.edu\/research\/drm2\/MITON-V0.2.zip."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Kolodenker, E., Koch, W., Stringhini, G., and Egele, M. (2017, January 2\u20136). PayBreak: Defense against cryptographic ransomware. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates.","DOI":"10.1145\/3052973.3053035"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Huang, J., Xu, J., Xing, X., Liu, P., and Qureshi, M.K. (November, January 30). FlashGuard: Leveraging Intrinsic Flash Properties to Defend Against Encryption Ransomware. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3134035"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Wang, P., Jia, S., Chen, B., Xia, L., and Liu, P. (2019, January 25\u201327). MimosaFTL: Adding Secure and Practical Ransomware Defense Strategy to Flash Translation Layer. Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy, CODASPY \u201919, Dallas, TX, USA.","DOI":"10.1145\/3292006.3300041"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Baek, S., Jung, Y., Mohaisen, A., Lee, S., and Nyang, D. (2018, January 2\u20135). SSD-insider: Internal defense of solid-state drive against ransomware with perfect data recovery. Proceedings of the 38th IEEE International Conference on Distributed Computing Systems, ICDCS 2018, Vienna, Austria.","DOI":"10.1109\/ICDCS.2018.00089"},{"key":"ref_34","first-page":"1762","article-title":"SSD-assisted Ransomware Detection and Data Recovery Techniques","volume":"70","author":"Baek","year":"2020","journal-title":"IEEE Trans. Comput."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1109\/LCA.2018.2883431","article-title":"Amoeba: An autonomous backup and recovery SSD for ransomware attack defense","volume":"17","author":"Min","year":"2018","journal-title":"IEEE Comput. Archit. Lett."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/2\/2\/17\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:18:59Z","timestamp":1760138339000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/2\/2\/17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,26]]},"references-count":35,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2022,6]]}},"alternative-id":["jcp2020017"],"URL":"https:\/\/doi.org\/10.3390\/jcp2020017","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,5,26]]}}}