返回
Android malware concept drift using system calls: Detection, characterization and challenges
DOI:10.1016/j.eswa.2022.117200.png)
摘要
En 中文
The majority of Android malware detection solutions have focused on the achievement of high performance in old and short snapshots of historical data, which makes them prone to lack the generalization and adaptation capabilities needed to discriminate effectively new malware trends in an extended time span. These approaches analyze the phenomenon from a stationary point of view, neglecting malware evolution and its degenerative impact on detection models as new data emerge, the so-called concept drift. This research proposes a novel method to detect and effectively address concept drift in Android malware detection and demonstrates the results in a seven-year-long data set. The proposed solution manages to keep high-performance metrics over a long period of time and minimizes model retraining efforts by using data sets belonging to short periods. Different timestamps are evaluated in the experimental setup and their impact on the detection performance is compared. Additionally, the characterization of concept drift in Android malware is performed by leveraging the inner workings of the proposed solution. In this regard, the discriminatory properties of the important features are analyzed at various time horizons.
Keyword:
Concept drift
Android malware
System calls
Mobile malware
Malware characterization
Malware detection
Malware evolution
Malware behavior
期刊
IF:
7.5
论文数:
3.0W
被引数:
10.2W
机构
引用论文
KronoDroid: Time-based Hybrid-featured Dataset for Effective Android Malware Detection and CharacterizationKronoDroid: 基于时间的混合特征数据集,用于有效的Android恶意软件检测和表征
COMPUTERS & SECURITY
IF5.4
A Review of Android Malware Detection Approaches Based on Machine Learning基于机器学习的Android恶意软件检测方法综述
IEEE ACCESS
IF3.6
Preprocessed dynamic classifier ensemble selection for highly imbalanced drifted data streams
INFORMATION FUSION
IF15.5
META-DES: A dynamic ensemble selection framework using meta-learningMeta-des: 一种基于元学习的动态集成选择框架
PATTERN RECOGNITION
IF7.6
MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral Models (Extended Version)MaMaDroid: 通过构建行为模型的马尔可夫链来检测Android恶意软件 (扩展版本)

