arrow
Return

S3Feature: A static sensitive subgraph-based feature for android malware detection

delete2022-01-01
delete26
PRE
AI
O
Ou, Fan
X
Xu, Jian *
DOI:10.1016/j.cose.2021.102513delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
As the most popular mobile platform, Android has become the major attack target of malware, and thus there is an urgent need to effectively thwart them. Recently, the machine learning-based technique has been a promising solution for malware detection, which highly depends on distinguishing features to separate the malware from the benign apps. Although hundreds of features are available for machine learning-based malware detectors, adversaries can also utilize feature-related knowledge to develop variants of malware to evade detection. Therefore, a key role of the Android security community is to continuously propose new features that can characterize malicious behaviors. In this paper, we propose a novel static sensitive subgraph-based feature for Android malware detection, named S(3)Featrue. First, to represent Android applications with high-level characteristics, we develop a sensitive function call graph (SFCG) by extending a function call graph (FCG) through tagging sensitive nodes on it. A malicious score is evaluated to identify sensitive nodes. Second, a large number of sensitive subgraphs (SSGs) and their neighbor subgraphs (NSGs) are mined from a SFCG to characterize suspicious behaviors of applications. Finally, after removing repetitive or isomorphic subgraphs, the remaining SSGs and NSGs are encoded into a feature vector to represent each application. For malware detection, S(3)Featrue achieves 97.04% F1-score, which performs better than other well-studied features. And a combination of S(3)Featrue and other features achieves 97.71% F1-score, which shows that S(3)Feature is a good potential feature in improving the performance of malware detection approaches or tools. (C) 2021 Elsevier Ltd. All rights reserved.
Keywords:
Malware detection
Semantic information
Sensitive subgraph
Machine learning
Feature engineering

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

No organization information available
Cited Papers

Cited Papers

errShare
errSave
errShare
errSave
Development of a Rechargeable Zinc-Air Battery
err2010-02-05
err0
errOAAI
errGwenaëlle Toussaint; Philippe Stevens; Florian Moureau; Robert Rouget; Fabrice Fourgeot
errShare
errSave
DAPASA: Detecting Android Piggybacked Apps Through Sensitive Subgraph Analysis
err2017-08-01
err110
PREAI
errFan, Ming; Liu, Jun; Wang, Wei; Li, Haifei; Tian, Zhenzhou; Liu, Ting
errShare
errSave
DroidChain: A novel Android malware detection method based on behavior chains
err2016-10-01
err22
PREAI
errWang, Zhaoguo; Li, Chenglong; Yuan, Zhenlong; Guan, Yi; Xue, Yibo
errShare
errSave
MADAM: Effective and Efficient Behavior-based Android Malware Detection and Prevention
err2018-01-01
err201
PREAI
errSaracino, Andrea; Sgandurra, Daniele; Dini, Gianluca; Martinelli, Fabio
errShare
errSave
Constructing Features for Detecting Android Malicious Applications: Issues, Taxonomy and Directions
err2019-01-01
err75
errOAAI
errWang, Wei; Zhao, Meichen; Gao, Zhenzhen; Xu, Guangquan; Xian, Hequn; Li, Yuanyuan; Zhang, Xiangliang
errShare
errSave
errShare
errSave
MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral Models (Extended Version)
err2019-04-09
err206
PREAI
errOnwuzurike, Lucky; Mariconti, Enrico; Andriotis, Panagiotis; De Cristofaro, Emiliano; Ross, Gordon; Stringhini, Gianluca
errShare
errSave
researcher View more