arrow
返回

Multi-class Malware Detection via Deep Graph Convolutional Networks Using TF-IDF-Based Attributed Call Graphs

delete2024-01-11
delete0
PRE
AI
I
Irshad Khan
Y
Youngwoo Kwon *
DOI:10.1007/978-981-99-8024-6_15delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The proliferation of malware in the Android ecosystem poses significant security risks and financial losses for enterprises and developers. Malware constantly evolves, exhibiting dynamic behavior and complexity, thus making it challenging to develop robust defense mechanisms. Traditional methods, such as signature-based and battery-monitoring approaches, struggle to detect emerging malware variants effectively. Recent advancements in deep learning have shown promising results in Android malware detection. However, most existing approaches focus on binary classification and need more insights into the model's generality across different types of malware. This study presents a novel approach to address Android malware detection by integrating TF-IDF (Term Frequency-Inverse Document Frequency) features into the call graph structure. By attributing each node in the call graph with TF-IDF-based feature vectors extracted from the opcode sequences of each method using an opcode list, we present a more thorough representation that encapsulates the complex traits of the malware samples. We employ state-of-the-art graph-based deep learning models to classify malware families, including Graph Convolutional Networks (GCN), SAGEConv, Graph Attention Networks (GAT), and Graph Isomorphism Networks (GIN). By incorporating high-level structural information from the call graphs and TF-IDF-based raw features, our approach aims to enhance the accuracy and generality of the malware detection models. We identify an optimal model for the Android malware family classification task through extensive evaluation and comparison of the above-mentioned models. The findings of this study contribute to advancing the field of Android malware detection and provide insights into the effectiveness of graph-based deep learning models for combating evolving malware threats.
Keyword:
Malware
TF-IDF
call graph
graph convolutional model

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

K
kyungpook national university (knu)
学者数:
1.8W
论文数: 1.8W
被引数: 14
引用论文

引用论文

Synthesis of raspberry-like magnetic polystyrene microspheres
err2007-06-01
err0
PREAI
errZhizhong Xu; Ao Xia; Changchun Wang; Wuli Yang; Shoukuang Fu
err分享
err收藏
err分享
err收藏
Introduction to Biophotonics
err
IF0
err2004-01-21
err0
PREAI
errParas N. Prasad
err分享
err收藏
Novel two-dimensional AlSb and InSb monolayers with a double-layer honeycomb structure: a first-principles study
err2021-01-01
err0
errOAAI
errA. Bafekry; M. Faraji; M. M. Fadlallah; H. R. Jappor; S. Karbasizadeh; M. Ghergherehchi; I. Abdolhosseini Sarsari; A. Abdolahzadeh Ziabari
err分享
err收藏
Dose Rate Effects on Radiolytic Synthesis of Gold−Silver Bimetallic Clusters in Solution
err1998-05-14
err0
PREAI
errM. Treguer; C. de Cointet; H. Remita; J. Khatouri; M. Mostafavi; J. Amblard; J. Belloni; R. de Keyzer
err分享
err收藏
err分享
err收藏
学者 查看更多内容