返回
Android Malware Detection Based on Informative Syscall Subsequences
DOI:10.1109/ACCESS.2024.3387475.png)
摘要
En 中文
The Android operating system commands a dominant market share of over 70% in the smartphone industry. However, this widespread usage has resulted in a concerning increase in malware applications. While existing static malware detection mechanisms are vulnerable to code obfuscation attacks, manipulating the runtime system call (syscall) sequence remains a significant challenge for attackers. Consequently, syscall-based malware detection mechanisms are gaining prominence. Current syscall-based malware detection approaches rely on machine learning algorithms, utilizing numerical features such as syscall frequencies and transition probability matrices. However, the wide range of values in these features necessitates large datasets for effective classifier training, and susceptibility to noise and outliers persists. As a result, there is an urgent need for a binary representation of dynamic features to improve malware detection efficiency. To address this challenge, our paper proposes an innovative syscall subsequence-based binary feature representation method for machine learning-driven malware detection. By employing the information gain method, we identify informative syscall subsequences. The proposed mechanism achieves an impressive 99% accuracy in detecting malware applications using just 50% of the training data, across both the Drebin/AMD and CICMalDroid2020 datasets.
Keyword:
Malware
Feature extraction
Smart phones
Training data
Classification algorithms
Androids
Machine learning algorithms
Operating systems
Runtime
Numerical analysis
Android
malware
system calls
machine learning
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Android Malware Familial Classification and Representative Sample Selection via Frequent Subgraph Analysis基于频繁子图分析的Android恶意软件家族分类及代表性样本选择
Intelligent Pattern Recognition Using Equilibrium Optimizer With Deep Learning Model for Android Malware Detection使用均衡优化器和深度学习模型进行智能模式识别,用于Android恶意软件检测
IEEE ACCESS
IF3.6

