返回
FAGnet: Family-aware-based android malware analysis using graph neural network
DOI:10.1016/j.knosys.2024.111531.png)
摘要
En 中文
Android malware family analysis is essential for building an efficient malware detection mechanism. In recent years, many graph representation learning -based malware detection and classification studies have been proposed, and many methods model malware as graph data to mine the behavioral semantics of malware. However, they do not consider the relationship at the sample (graph) level, and malware belonging to the same family has similar malicious behavior. The transformation of samples according to the Data Processing Inequality (DPI) will lead to the loss of mutual information transmission, which inspired us to consider the analysis of malware based on graph representation learning from this perspective. In this paper, we consider introducing the relationship between malware samples, inserting a family representation refinement component that is conducive to improving the family separability in the graph classification task, and propose a Family -Aware Graph neural network Android malware analysis (FAGnet). We use 4 backbones to perform extension experiments on 2 benchmark datasets and comprehensively compare some baseline methods. The experiments verify the effectiveness of FAGnet, which achieves 98.11 % accuracy on the Drebin dataset and 83.45 % and 72.76 % accuracy on the CICAndMal2017 category and family classification, respectively. In addition, FAGnet is evaluated with real -world data, and its satisfactory performance was maintained in real -world scenarios.
Keyword:
Android malware analysis
Malware family
Graph neural network
Graph classification
Static code analysis
期刊
K
IF:
7.6
论文数:
1.3W
被引数:
4.5W
机构
引用论文
Android Malware Familial Classification and Representative Sample Selection via Frequent Subgraph Analysis基于频繁子图分析的Android恶意软件家族分类及代表性样本选择
DMalNet: Dynamic malware analysis based on API feature engineering and graph learningDMalNet: 基于API特征工程和图学习的动态恶意软件分析
COMPUTERS & SECURITY
IF5.4
GDroid: Android malware detection and classification with graph convolutional networkGDroid: 使用图卷积网络进行Android恶意软件检测和分类
COMPUTERS & SECURITY
IF5.4
Semi-supervised two-phase familial analysis of Android malware with normalized graph embedding基于归一化图嵌入的Android恶意软件半监督两阶段家族分析
没有更多内容

