Identifying Android Malware Using Network-Based Approaches

Identifying Android Malware Using Network-Based Approaches
复制标题

DOI:
10.1145/3341161.3343534
复制
发表时间:
2019-07
期刊:
2019 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM)
影响因子:
--
通讯作者:
Emily Alfs;Doina Caragea;Nathan Albin;P. Poggi-Corradini
Emily Alfs;Doina Caragea;Nathan Albin;P. Poggi-Corradini
中科院分区:
其他
文献类型:
--
作者:
Emily Alfs;Doina Caragea;Nathan Albin;P. Poggi-Corradini

文献摘要

相似文献

Android应用程序的激增导致许多恶意应用程序进入市场并造成重大损害。非常需要确定应用程序是否是恶意的强大技术。我们建议使用基于网络的方法,基于小型标记数据集有效地区分恶意应用程序和良性应用程序。我们数据集中的应用程序来自Google Play商店,并已使用VirusTotal扫描恶意行为,以生成带有恶意或良性标签的地面实况数据集。结果数据集中的应用程序以二进制特征向量的形式表示(其中特征表示权限、意图操作、区分性API、混淆签名和本机代码签名)。我们使用这些向量来构建一个加权网络,以捕捉应用程序之间的“亲密度”。我们将标签从标记的应用程序传播到未标记的应用程序,并使用Fl度量评估研究方法的有效性。我们已经进行了实验,以比较标签传播方法的三种变体在由越来越多的标记数据组成的数据集上。
The proliferation of Android applications has resulted in many malicious apps entering the market and causing significant damage. Robust techniques that determine if an app is malicious are greatly needed. We propose the use of network-based approaches to effectively separate malicious from benign apps, based on a small labeled dataset. The apps in our dataset come from the Google Play Store and have been scanned for malicious behavior using VirusTotal to produce a ground truth dataset with labels malicious or benign. The apps in the resulting dataset have been represented in the form of binary feature vectors (where the features represent permissions, intent actions, discriminative APIs, obfuscation signatures, and native code signatures). We have used these vectors to build a weighted network that captures the “closeness” between apps. We propagate labels from the labeled apps to unlabeled apps, and evaluate the effectiveness of the approaches studied using the Fl-measure. We have conducted experiments to compare three variants of the label propagation approaches on datasets that consist of increasingly larger amounts of labeled data.