返回
HGDetector: A hybrid Android malware detection method using network traffic and Function call graph
DOI:10.1016/j.aej.2024.11.068.png)
摘要
En 中文
The malicious infestations of Android malware caused huge economic losses to users over the past few years. Machine learning-based malware detection enhances the accuracy and partially mitigates these security threats. However, when the static or dynamic features cannot effectively represent software behavior, the accuracy of the model will be reduced. For this issue, a multi-features hybrid malware detection and category classification method HGDetector is proposed, this approach provides a more comprehensive representation of software behavior. HGDetector first extracts the software static function call graph and constructs the network behavior function call graph, then applies the dynamic network traffic features of the software to build the node interaction graph and edge-node graph; Subsequently, these features were fused and converted into a vector representation employing graph embedding method; Finally, combined with the proposed HGDetector, different classifiers were used to test the accuracy of malware detection and category classification. The experimental results demonstrate that the fusion of hybrid features can enhance malware detection accuracy by approximately 4 % when network traffic features effectively capture APP's behavior. Conversely, in cases where network traffic features alone are insufficient to represent software's network behavior, the application of hybrid features can improve malware detection accuracy by 21 %-26 %.
Keyword:
Android
Malware detection
Multi-features hybrid
Graph
期刊
IF:
6.8
论文数:
6.3K
被引数:
2.6W
机构
引用论文
IoT malware classification based on reinterpreted function-call graphs基于重新解释的函数调用图的物联网恶意软件分类
COMPUTERS & SECURITY
IF5.4
Explainable Malware Detection System Using Transformers-Based Transfer Learning and Multi-Model Visual Representation使用基于Transformers的迁移学习和多模型视觉表示的可解释恶意软件检测系统
SENSORS
IF3.5
Hybrid Android Malware Detection: A Review of Heuristic-Based Approach混合Android恶意软件检测: 基于启发式的方法综述
IEEE ACCESS
IF3.6

