Hybrid Analysis of Android Apps for Security Vetting using Deep Learning

Hybrid Analysis of Android Apps for Security Vetting using Deep Learning
复制标题

DOI:
10.1109/cns48642.2020.9162341
复制
发表时间:
2020-06
期刊:
2020 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Dewan Chaulagain;Prabesh Poudel;Prabesh Pathak;Sankardas Roy;Doina Caragea;G. Liu;Xinming Ou
Dewan Chaulagain;Prabesh Poudel;Prabesh Pathak;Sankardas Roy;Doina Caragea;G. Liu;Xinming Ou
中科院分区:
其他
文献类型:
--
作者:
Dewan Chaulagain;Prabesh Poudel;Prabesh Pathak;Sankardas Roy;Doina Caragea;G. Liu;Xinming Ou

文献摘要

被引文献

相似文献

近年来,Android设备使用量的惊人增长也伴随着Android恶意软件的兴起。这一现实需要开发工具和技术来大规模分析Android应用程序,以进行安全审查。大多数最先进的审查工具要么基于静态分析,要么基于动态分析。如果恶意软件应用程序使用复杂的规避技巧,静态分析的成功是有限的。另一方面,动态分析可能无法找到所有代码执行路径,这使得一些恶意软件应用程序无法被检测到。此外,现有的静态和动态分析审查技术需要广泛的人工交互。为了解决上述问题,我们设计了一种基于深度学习的混合分析技术,它结合了每种分析范例的互补优势,以获得更好的准确率。此外,深度学习框架的自动化特征工程能力解决了人类交互问题。特别是,利用轻量级的静态和动态分析过程,我们获得了多个人工产物,并利用这些人工产物训练深度学习器来创建独立的模型,然后将它们结合起来构建混合分类器,以获得最终的审查决策(恶意应用与良性应用)。实验表明,采用混合分析的最优深度学习模型的准确率-召回率曲线达到了0.9998以下。在本文中,我们还提出了对深度学习框架的不同变体的绩效测量的比较研究。额外的实验表明,我们的审查系统对不平衡数据具有相当的健壮性和可伸缩性。
The phenomenal growth in use of android devices in the recent years has also been accompanied by the rise of android malware. This reality warrants development of tools and techniques to analyze android apps in large scale for security vetting. Most of the state-of-the-art vetting tools are either based on static analysis or on dynamic analysis. Static analysis has limited success if the malware app utilizes sophisticated evading tricks. Dynamic analysis on the other hand may not find all the code execution paths, which let some malware apps remain undetected. Moreover, the existing static and dynamic analysis vetting techniques require extensive human interaction. To address the above issues, we design a deep learning based hybrid analysis technique, which combines the complementary strengths of each analysis paradigm to attain better accuracy. Moreover, automated feature engineering capability of the deep learning framework addresses the human interaction issue. In particular, using lightweight static and dynamic analysis procedure, we obtain multiple artifacts, and with these artifacts we train the deep learner to create independent models, and then combine them to build a hybrid classifier to obtain the final vetting decision (malicious apps vs. benign apps). The experiments show that our best deep learning model with hybrid analysis achieves an area under the precision-recall curve (AUC) of 0.9998. In this paper, we also present a comparative study of performance measures of the various variants of the deep learning framework. Additional experiments indicate that our vetting system is fairly robust against imbalanced data and is scalable.