OpCode-Level Function Call Graph Based Android Malware Classification Using Deep Learning

OpCode-Level Function Call Graph Based Android Malware Classification Using Deep Learning
复制标题

使用深度学习进行基于操作码级函数调用图的 Android 恶意软件分类

DOI:
10.3390/s20133645
复制
发表时间:
2020-06
期刊:
影响因子:
3.9
通讯作者:
Ting Li
Ting Li
中科院分区:
综合性期刊3区
文献类型:
--
作者:
Weina Niu;Rong Cao;Xiaosong Zhang;Kangyi Ding;Kaimeng Zhang;Ting Li

文献摘要

参考文献

相似文献

由于安卓系统的开放性,许多物联网(IoT)设备都在运行安卓系统,并且由于安卓设备上有各种传感器,它们已成为物联网设备常见的控制终端。随着物联网设备的普及,基于安卓的物联网设备上的恶意软件也在增加,人们的生活和隐私安全受到威胁。为了减少这种威胁,许多研究人员提出了检测安卓恶意软件的新方法。目前,市场上大多数恶意软件检测产品基于恶意软件特征码,对于已知的恶意软件家族,它们检测速度快,误报率通常较低。然而,它们无法检测未知的恶意软件,并且容易被混淆或打包的恶意软件规避。许多新的解决方案使用句法特征和机器学习技术对安卓恶意软件进行分类。众所周知,对函数调用图(FCG)的分析能够很好地捕捉恶意软件的行为特征。本文提出了一种基于深度学习和操作码级FCG对安卓恶意软件进行分类的新方法。FCG是通过对操作码(OpCode)进行静态分析获得的,我们使用的深度学习模型是长短期记忆网络(LSTM)。我们在一个数据集上进行了实验,该数据集包含1796个分为两类的安卓恶意软件样本(从Virusshare和AndroZoo获取)以及1000个良性安卓应用。我们的实验结果表明,我们提出的方法准确率为97%,优于Nikola等人和Hou等人(IJCAI - 18)提出的最先进的方法,他们的准确率分别为97%和91%。我们提出的方法所消耗的时间比其他两种方法少。
Due to the openness of an Android system, many Internet of Things (IoT) devices are running the Android system and Android devices have become a common control terminal for IoT devices because of various sensors on them. With the popularity of IoT devices, malware on Android-based IoT devices is also increasing. People’s lives and privacy security are threatened. To reduce such threat, many researchers have proposed new methods to detect Android malware. Currently, most malware detection products on the market are based on malware signatures, which have a fast detection speed and normally a low false alarm rate for known malware families. However, they cannot detect unknown malware and are easily evaded by malware that is confused or packaged. Many new solutions use syntactic features and machine learning techniques to classify Android malware. It has been known that analysis of the Function Call Graph (FCG) can capture behavioral features of malware well. This paper presents a new approach to classifying Android malware based on deep learning and OpCode-level FCG. The FCG is obtained through static analysis of Operation Code (OpCode), and the deep learning model we used is the Long Short-Term Memory (LSTM). We conducted experiments on a dataset with 1796 Android malware samples classified into two categories (obtained from Virusshare and AndroZoo) and 1000 benign Android apps. Our experimental results showed that our proposed approach with an accuracy of 97 % outperforms the state-of-the-art methods such as those proposed by Nikola et al. and Hou et al. (IJCAI-18) with the accuracy of 97 % and 91 % , respectively. The time consumption of our proposed approach is less than the other two methods.
DOI: 10.1109/sarnof.2016.7846747
发表时间: 2016-09
期刊: 2016 IEEE 37th Sarnoff Symposium
影响因子: --
作者:
Zi Wang;Juecong Cai;Sihua Cheng;Wenjia Li
通讯作者: Zi Wang;Juecong Cai;Sihua Cheng;Wenjia Li
DOI: 10.1109/tse.2016.2615307
发表时间: 2017-06
影响因子: 7.4
作者:
Alireza Sadeghi;H. Bagheri;Joshua Garcia;S. Malek
通讯作者: Alireza Sadeghi;H. Bagheri;Joshua Garcia;S. Malek
DOI: 10.1109/asiajcis.2012.18
发表时间: 2012-08
期刊: 2012 Seventh Asia Joint Conference on Information Security
影响因子: --
作者:
Dong-Jie Wu;Ching-Hao Mao;Te-En Wei;Hahn-Ming Lee;Kuo-Ping Wu
通讯作者: Dong-Jie Wu;Ching-Hao Mao;Te-En Wei;Hahn-Ming Lee;Kuo-Ping Wu
DOI: 10.24963/ijcai.2018/737
发表时间: 2018-07
期刊: --
影响因子: --
作者:
Shifu Hou;Yanfang Ye;Yangqiu Song;Melih Abdulhayoglu
通讯作者: Shifu Hou;Yanfang Ye;Yangqiu Song;Melih Abdulhayoglu
DOI: 10.14722/ndss.2014.23039
发表时间: 2014
期刊: --
影响因子: --
作者:
Siegfried Rasthofer;Steven Arzt;E. Bodden
通讯作者: Siegfried Rasthofer;Steven Arzt;E. Bodden