返回
S3Feature: A static sensitive subgraph-based feature for android malware detection
DOI:10.1016/j.cose.2021.102513.png)
摘要
En 中文
As the most popular mobile platform, Android has become the major attack target of malware, and thus there is an urgent need to effectively thwart them. Recently, the machine learning-based technique has been a promising solution for malware detection, which highly depends on distinguishing features to separate the malware from the benign apps. Although hundreds of features are available for machine learning-based malware detectors, adversaries can also utilize feature-related knowledge to develop variants of malware to evade detection. Therefore, a key role of the Android security community is to continuously propose new features that can characterize malicious behaviors. In this paper, we propose a novel static sensitive subgraph-based feature for Android malware detection, named S(3)Featrue. First, to represent Android applications with high-level characteristics, we develop a sensitive function call graph (SFCG) by extending a function call graph (FCG) through tagging sensitive nodes on it. A malicious score is evaluated to identify sensitive nodes. Second, a large number of sensitive subgraphs (SSGs) and their neighbor subgraphs (NSGs) are mined from a SFCG to characterize suspicious behaviors of applications. Finally, after removing repetitive or isomorphic subgraphs, the remaining SSGs and NSGs are encoded into a feature vector to represent each application. For malware detection, S(3)Featrue achieves 97.04% F1-score, which performs better than other well-studied features. And a combination of S(3)Featrue and other features achieves 97.71% F1-score, which shows that S(3)Feature is a good potential feature in improving the performance of malware detection approaches or tools. (C) 2021 Elsevier Ltd. All rights reserved.
Keyword:
Malware detection
Semantic information
Sensitive subgraph
Machine learning
Feature engineering
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
暂无机构信息
引用论文
Android based malware detection using a multifeature collaborative decision fusion approach基于多特征协同决策融合方法的Android恶意软件检测
NEUROCOMPUTING
IF6.5
Android Malware Familial Classification and Representative Sample Selection via Frequent Subgraph Analysis基于频繁子图分析的Android恶意软件家族分类及代表性样本选择
Amandroid: A Precise and General Inter-component Data Flow Analysis Framework for Security Vetting of Android AppsAmandroid: 一种用于Android应用安全审查的精确通用组件间数据流分析框架
MADAM: Effective and Efficient Behavior-based Android Malware Detection and PreventionMADAM: 有效和高效的基于行为的Android恶意软件检测和预防
Constructing Features for Detecting Android Malicious Applications: Issues, Taxonomy and Directions构建用于检测Android恶意应用程序的功能: 问题,分类和方向
IEEE ACCESS
IF3.6

