返回
FAM: Featuring Android Malware for Deep Learning-Based Familial Analysis
DOI:10.1109/ACCESS.2022.3151357.png)
摘要
En 中文
To handle relentlessly emerging Android malware, deep learning has been widely adopted in the research community. Prior work proposed deep learning-based approaches that use different features of malware, and reported a high accuracy in malware detection, i.e., classifying malware from benign applications. However, familial analysis of real-world Android malware has not been extensively studied yet. Familial analysis refers to the process of classifying a given malware into a family (or a set of families), which can greatly accelerate malware analysis as the analysis gives their fine-grained behavioral characteristics. In this work, we shed light on deep learning-based familial analysis by studying different features of Android malware and how effectively they can represent their (malicious) behaviors. We focus on string features of Android malware, namely the Abstract Syntax Trees (AST) of all functions extracted from each malware, which faithfully represent all string features of Android malware. We thoroughly study how different string features, such as how security-sensitive APIs are used in malware, affect the performance of our deep learning-based familial analysis model. A convolutional neural network was trained and tested in various configurations on 28,179 real-world malware dataset appeared in the wild from 2018 to 2020, where each malware has one or more labels assigned based on their behaviors. Our evaluation reveals how different features contribute to the performance of familial analysis. Notably, with all features combined, we were able to produce up to an accuracy of 98% and a micro F1-score of 0.82, a result on par with the state-of-the-art.
Keyword:
Malware
Feature extraction
Deep learning
Analytical models
Security
Codes
Training
Malware classification
deep learning
Android security
abstract syntax tree
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Android Malware Familial Classification and Representative Sample Selection via Frequent Subgraph Analysis基于频繁子图分析的Android恶意软件家族分类及代表性样本选择
Semi-supervised two-phase familial analysis of Android malware with normalized graph embedding基于归一化图嵌入的Android恶意软件半监督两阶段家族分析

