Out-of-sample Node Representation Learning for Heterogeneous Graph in Real-time Android Malware Detection

Out-of-sample Node Representation Learning for Heterogeneous Graph in Real-time Android Malware Detection
复制标题

DOI:
10.24963/ijcai.2019/576
复制
发表时间:
2019-08
期刊:
Int. J. Pattern Recognit. Artif. Intell.
影响因子:
--
通讯作者:
Yanfang Ye;Shifu Hou;Lingwei Chen;Jingwei Lei;Wenqiang Wan;Jiabin Wang;Qi Xiong;Fudong Shao
Yanfang Ye;Shifu Hou;Lingwei Chen;Jingwei Lei;Wenqiang Wan;Jiabin Wang;Qi Xiong;Fudong Shao
中科院分区:
其他
文献类型:
--
作者:
Yanfang Ye;Shifu Hou;Lingwei Chen;Jingwei Lei;Wenqiang Wan;Jiabin Wang;Qi Xiong;Fudong Shao

文献摘要

被引文献

相似文献

越来越复杂的Android恶意软件要求采用新的防御技术,这些技术能够保护移动用户免受新型威胁。在本文中,我们首先从Android应用程序提取运行时应用程序编程接口(API)调用序列,然后分析生态系统内的高级语义关系,以全面地表征应用程序。为了建模不同类型的实体(即应用程序,API,设备,签名,隶属关系)及其之间的丰富关系,我们提出了一个结构化的异质图(HG),用于建模。要在构造的HG中有效地对节点(例如应用程序)进行分类,我们建议使用HG学习方法首先获得样本中的节点嵌入,然后在第一次尝试中重新尝试/调整HG嵌入的情况下样本外节点的表示形式。后来,我们设计了一个深度神经网络分类器,将学习的HG表示作为实时Android恶意软件检测的输入。对腾讯安全实验室的大规模和实际样品集进行了全面的实验,以比较各种基准。有希望的结果表明,我们开发的系统AIDORID整合我们所提出的方法在实时的Android恶意软件检测中优于其他人。
The increasingly sophisticated Android malware calls for new defensive techniques that are capable of protecting mobile users against novel threats. In this paper, we first extract the runtime Application Programming Interface (API) call sequences from Android apps, and then analyze higher-level semantic relations within the ecosystem to comprehensively characterize the apps. To model different types of entities (i.e., app, API, device, signature, affiliation) and rich relations among them, we present a structured heterogeneous graph (HG) for modeling. To efficiently classify nodes (e.g., apps) in the constructed HG, we propose the HG-Learning method to first obtain in-sample node embeddings and then learn representations of out-of-sample nodes without rerunning/adjusting HG embeddings at the first attempt. We later design a deep neural network classifier taking the learned HG representations as inputs for real-time Android malware detection. Comprehensive experiments on large-scale and real sample collections from Tencent Security Lab are performed to compare various baselines. Promising results demonstrate that our developed system AiDroid which integrates our proposed method outperforms others in real-time Android malware detection.