返回
Android malware detection using time-aware machine learning approach
DOI:10.1007/s10586-024-04484-6.png)
摘要
En 中文
In today's rapidly evolving digital landscape, the surge in smartphone usage is paralleled by an increasing wave of cyberthreats, highlighting the limitations of existing signature-based malware detection methods. To address this problem, our research introduces a Time-Aware Machine Learning (TAML) framework specifically designed for Android malware detection. Our framework extracts the best time-correlated features and then it builds time-aware and time-agnostic machine learning (ML) models. The ML models are trained on the KronoDroid dataset, which contains more than 41,000 benign Android apps and more than 36,000 malicious apps developed between 2008 to 2020. Our experimental evaluation revealed that the Last Modification Date 'LastModDate' feature is a critical variable for time-aware classification. Moreover, our empirical analysis reveals that real-device detection outperforms emulator-based detection. Impressively, the time-correlated features boosts the detection performance and achieving an outstanding 99.98% F1 score in a time-agnostic setting. In addition, on each year, our time-aware experiments outperformed the traditional ML detection models. Our time-aware classifier achieved a 91% F1 score on average and a maximum F1 score of 99% of yearly chunk experiments over 12 years. These experimental results affirm the effectiveness of our proposed method in detecting Android malware.
Keyword:
Time-aware machine learning (TAML)
Android malware detection
Temporal intelligence
Cybersecurity
Temporal feature extraction
Concept drift
Binary classification
Multiclass classification
KronoDroid dataset
Mobile security
Temporal weighting
Real-device testing
Signature-based detection
期刊
C
IF:
4.1
论文数:
5.0K
被引数:
7.5K
机构
引用论文
What are health professionals’ intentions toward using research and products of research in clinical practice? A systematic review and narrative synthesis
Nursing Open
IF0
KronoDroid: Time-based Hybrid-featured Dataset for Effective Android Malware Detection and CharacterizationKronoDroid: 基于时间的混合特征数据集,用于有效的Android恶意软件检测和表征
COMPUTERS & SECURITY
IF5.4
A comprehensive survey on deep learning based malware detection techniques基于深度学习的恶意软件检测技术综述
COMPUTER SCIENCE REVIEW
IF12.7
Malware Detection: A Framework for Reverse Engineered Android Applications Through Machine Learning Algorithms恶意软件检测: 通过机器学习算法进行逆向工程的Android应用程序框架
IEEE ACCESS
IF3.6
Search for a light scalar top squark ine+e−reactions atEc.m.=58 GeV在Ecm=58 GeV的e⁺e⁻反应中搜索轻标量顶 slepton

