返回
Learning to detect Android malware via opcode sequences
DOI:10.1016/j.neucom.2018.09.102.png)
摘要
En 中文
A large number of Android malware samples can be deployed as the variants of the previously known samples. In consequence, a classification system capable of supporting a large set of samples is required to secure Android platform. Although a large set of variants requires scalability for automatic detection and classification, it also presents a significant advantage about a richer dataset at the stage of discovering underlying malicious activities and extracting representative features. Deep Neural Networks are built by a complex structure of layers whose parameters can be tuned and trained in order to enhance classification statistical metric results. Emerging parallelization computing tools and processors reduce computation time. In this paper, we propose a deep learning Android malware detection method using features extracted from instruction call graphs. The presented method examines all possible execution paths and the balanced dataset improves deep neural learning benign execution paths versus malicious paths. Since there is not a publicly available model for Android malware detection, we train deep networks from scratch. Then, we apply a grid search method to seek the optimal parameters of the network and to discover the combination of the hyper-parameters, which maximizes the statistical metric values. To validate the effectiveness of the proposed method, we evaluate with a balanced dataset constituted by 24,650 malicious and 25,0 00 benign samples. We evaluate the deep network architecture with respect to different parameters and compare the statistical metric values including runtime with respect to baseline classifiers. Our experimental results show that the presented malware detection is reached at 91.42% level in accuracy and 91.91% in F-measure, respectively. (C) 2019 Elsevier B.V. All rights reserved.
Keyword:
Android malware
Deep learning
Instruction call graph
Neural network
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
6.5
论文数:
2.5W
被引数:
6.5W
机构
引用论文
Early-stage malware prediction using recurrent neural networks基于递归神经网络的早期恶意软件预测
COMPUTERS & SECURITY
IF5.4
MADAM: Effective and Efficient Behavior-based Android Malware Detection and PreventionMADAM: 有效和高效的基于行为的Android恶意软件检测和预防


