返回
Enhancing android malware detection explainability through function call graph APIs
DOI:10.1016/j.jisa.2023.103691.png)
摘要
En 中文
Nowadays, mobile devices are massively used in everyday activities. Thus, they contain sensitive data targeted by threat actors like bank accounts and personal information. Through the years, Machine Learning approaches have been proposed to identify malicious Android applications, but recent research highlights the need for better explanations for model decisions, as existing ones may not be related to the app's malicious functionalities. This paper proposes an explainable approach based on static analysis to detect Android malware. The novelty lies in the specific analysis conducted to select and extract the features (i.e., APIs taken from the DEX Call Graph) that immediately provide meaningful explanations of the model functionality, thus allowing a significant correlation of the malware behavior with its family. Moreover, since we contain the number and type of features, the distinct impacts of each one appear more evident. The attained results show that it is possible to reach comparable results (in terms of accuracy) to existing state-of-the-art models while providing easy -to -understand explanations, which may yield significant insights into the malicious functionalities of the samples.
Keyword:
Malware analysis
Deep learning
Explainability
Android
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.7
论文数:
1.9K
被引数:
4.9K
机构
引用论文
UNC9426, A SELECTIVE TYRO3 INHIBITOR, DECREASES HUMAN PLATELET ACTIVATION AND INCREASES SURVIVAL IN A MURINE PULMONARY EMBOLISM MODELUNC9426,一种选择性TYRO3抑制剂,可降低人血小板活化并增加小鼠肺栓塞模型中的存活率。
PAIRED: An Explainable Lightweight Android Malware Detection System配对: 一个可解释的轻量级Android恶意软件检测系统
IEEE ACCESS
IF3.6
Explainable Malware Detection System Using Transformers-Based Transfer Learning and Multi-Model Visual Representation使用基于Transformers的迁移学习和多模型视觉表示的可解释恶意软件检测系统
SENSORS
IF3.5
Towards an interpretable deep learning model for mobile malware detection and family identification面向移动恶意软件检测和家族识别的可解释深度学习模型
COMPUTERS & SECURITY
IF5.4
没有更多内容

