Make Evasion Harder: An Intelligent Android Malware Detection System

Make Evasion Harder: An Intelligent Android Malware Detection System
复制标题

DOI:
10.24963/ijcai.2018/737
复制
发表时间:
2018-07
期刊:
--
影响因子:
--
通讯作者:
Shifu Hou;Yanfang Ye;Yangqiu Song;Melih Abdulhayoglu
Shifu Hou;Yanfang Ye;Yangqiu Song;Melih Abdulhayoglu
中科院分区:
其他
文献类型:
--
作者:
Shifu Hou;Yanfang Ye;Yangqiu Song;Melih Abdulhayoglu

文献摘要

被引文献

相似文献

为了对抗不断发展的Android恶意软件攻击,本文不再仅仅使用应用程序编程接口(API)调用,而是进一步分析它们之间的不同关系,并创建更高级别的语义,这需要攻击者付出更多努力来逃避检测。我们将Android应用程序(app)、相关API及其丰富的关系表示为结构化异构信息网络(HIN)。然后,我们使用基于元路径的方法来表征应用程序和API的语义相关性。我们使用每个元路径来制定Android应用程序的相似性度量,并使用多内核学习来聚合不同的相似性以进行预测。基于Comodo云安全中心的真实的样本收集的实验结果表明,我们开发的系统HinDroid优于其他替代Android恶意软件检测技术。
To combat the evolving Android malware attacks, in this paper, instead of only using Application Programming Interface (API) calls, we further analyze the different relationships between them and create higher-level semantics which require more efforts for attackers to evade the detection. We represent the Android applications (apps), related APIs, and their rich relationships as a structured heterogeneous information network (HIN). Then we use a meta-path based approach to characterize the semantic relatedness of apps and APIs. We use each meta-path to formulate a similarity measure over Android apps, and aggregate different similarities using multi-kernel learning to make predictions. Promising experimental results based on real sample collections from Comodo Cloud Security Center demonstrate that our developed system HinDroid outperforms other alternative Android malware detection techniques.