返回
Dalvik Opcode Graph Based Android Malware Variants Detection Using Global Topology Features
DOI:10.1109/ACCESS.2018.2870534.png)
摘要
En 中文
Since Android has become the dominator of smartphone operating system market with a share of 86.8%, the number of Android malicious applications are increasing rapidly as well. Such a large volume of diversified malware variants has forced researchers to investigate new methods by using machine learning since it provides a powerful ability for variants detection. Since the static analysis of malware plays an important role in system security and the opcode has been shown as an effective representation of malware, some of them use the Dalvik opcodes as features of malware and adopt machine learning to detect Android malware. However, current opcode-based methods are also facing some problems, such as considering both of accuracy and time cost, selection of features, and the lack of understanding or description of the characteristics of malware. To overcome the existing challenges, we propose a novel method to build a graph of Dalvik opcode and analyze its global topology properties, which will first construct a weighted probability graph of operations, and then we use information entropy to prune this graph while retaining information as more as possible, the next we extract several global topology features of the graph to represent malware, finally search the similarities with these features between programs. These global topology features formulate the high-level characteristics of malware. Our approach provides a light weight framework to detect Android malware variants based on graph theory and information theory. Theoretical analysis and real-life experimental results show the effectiveness, efficiency, and robustness of our approach, which achieves high detection accuracy and cost little training and detection time.
Keyword:
Dalvik opcode graph
global topology features
information theory
similarity searching
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Android Malware Familial Classification and Representative Sample Selection via Frequent Subgraph Analysis基于频繁子图分析的Android恶意软件家族分类及代表性样本选择
A new EV71 VP3 epitope in norovirus P particle vector displays neutralizing activity and protection in vivo in mice
Vaccine
IF0
MOCDroid: multi-objective evolutionary classifier for Android malware detectionMOCDroid: 用于Android恶意软件检测的多目标进化分类器
SOFT COMPUTING
IF2.5

