arrow
返回

Android malware obfuscation variants detection method based on multi-granularity opcode features

delete2022-04-01
delete40
PRE
AI
汤俊伟 封面图
汤俊伟 (Junwei Tang)
R
Ruixuan Li *
Y
Yu Jiang
辜希武 (Xiwu Gu)
Y
Yuhua Li
DOI:10.1016/j.future.2021.11.005delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Android malware poses a serious security threat to ordinary mobile users. However, the obfuscation technology can generate malware variants, which can bypass existing detection methods and significantly reduce detection accuracy. Aiming at the detection of Android malware obfuscation variants, we propose an efficient anti-obfuscation Android malware detection system MGOPDroid. For different obfuscation technologies, MGOPDroid extracts opcode features with different granularities, combines the TFIDF algorithm and the difference index of opcode feature distribution before and after obfuscation to calculates the weight of opcode features. Then we convert the opcode features into the sequences according to the opcode encoding mapping rules and convert the sequences into grayscale images to achieve feature visualization. A deep learning detection model combined with image enhancement, Resnet, and global average pooling layer is designed to detect malware variants. What is more, MGOPDroid can be deployed on mobile devices, supports real-time monitoring of application installation and update behavior, and automatically detect malware. Experiments show that the malware detection accuracy for unobfuscated samples is 96.35%, and is 94.55% for the obfuscated malware. And malware family classification accuracy is 95.31%, while after obfuscating, the classification accuracy rate is 89.96%. On mobile devices, the average time to detect a single application is 3.211 s. Compared with the previous advanced methods, MGOPDroid has obvious advantages in anti-obfuscation effect and efficiency. (C) 2021 Elsevier B.V. All rights reserved.
Keyword:
Android security
Malware family
Obfuscation
Malware detection

期刊

F
Future Generation Computer Systems-The International Journal of eScience
IF:
6.1
论文数:
6.8K
被引数:
2.3W

机构

暂无机构信息
引用论文

引用论文

err分享
err收藏