arrow
返回

A pragmatic android malware detection procedure

delete2017-09-01
delete25
PRE
AI
P
Paolo Palumbo
L
Luiza Sayfullina
D
Dmitriy Komashinskiy
E
Eirola, Emil *
J
Juha Karhunen
DOI:10.1016/j.cose.2017.07.013delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The academic security research community has studied the Android malware detection problem extensively. Machine learning methods proposed in previous work typically achieve high reported detection performance on fixed datasets. Some of them also report reasonably fast prediction times. However, most of them are not suitable for real-world deployment because requirements for malware detection go beyond these figures of merit. In this paper, we introduce several important requirements for deploying Android malware detection systems in the real world. One such requirement is that candidate approaches should be tested against a stream of continuously evolving data. Such streams of evolving data represent the continuous flow of unknown file objects received for categorization, and provide more reliable and realistic estimate of detection performance once deployed in a production environment. As a case study we designed and implemented an ensemble approach for automatic Android malware detection that meets the real-world requirements we identified. Atomic Naive Bayes classifiers used as inputs for the Support Vector Machine ensemble are based on different APK feature categories, providing fast speed and additional reliability against the attackers due to diversification. Our case study with several malware families showed that different families are detected by different atomic classifiers. To the best of our knowledge, our work contains the first publicly available results generated against evolving data streams of nearly 1 million samples with a model trained over a massive sample set of 120,000 samples. (C) 2017 Elsevier Ltd. All rights reserved.
Keyword:
Android
Malware detection
Static analysis
Machine learning
Classification
Ensemble learning
Feature selection
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

A
Aalto University
学者数:
1.6W
论文数: 1.5W
被引数: 2.1W
Arcada University of Applied Sciences 封面图
Arcada University of Applied Sciences
学者数:
72
论文数: 81
被引数: 65
引用论文

引用论文

DENDROID: A text mining approach to analyzing and classifying code structures in Android malware families
err2014-03-01
err179
errOAAI
errSuarez-Tangil, Guillermo; Tapiador, Juan E.; Pens-Lopez, Pedro; Blasco, Jorge
err分享
err收藏
Support-vector networks支持向量网络
err1995-09-01
err0
errOAAI
errCorinna Cortes; Vladimir Vapnik
err分享
err收藏