Android malware detection method based on highly distinguishable static features and DenseNet

Author:

Yang Jiyun,Zhang ZhiboORCID,Zhang Heng,Fan JiaWen

Abstract

The rapid growth of malware has become a serious problem that threatens the security of the mobile ecosystem and needs to be studied and resolved. Android is the main target of attackers due to its open source and popularity. To solve this serious problem, an accurate and efficient malware detection method is needed. Most existing methods use a single type of feature, which can be easily bypassed, resulting in low detection accuracy. In addition, although multiple types of features are used in some methods to solve the drawbacks of detection methods using a single type of feature, there are still some problems. Firstly, due to multiple types of features, the number of features in the initial feature set is extremely large, and some methods directly use them for training, resulting in excessive overhead. Furthermore, some methods utilize feature selection to reduce the dimensionality of features, but they do not select highly distinguishable features, resulting in poor detection performance. In this article, an effective and accurate method for identifying Android malware, which is based on an analysis of the use of seven types of static features in Android is proposed to cope with the rapid increase in the amount of Android malware and overcome the drawbacks of detection methods using a single type of feature. Instead of utilizing all extracted features, we design three levels of feature selection methods to obtain highly distinguishable features that can be effective in identifying malware. Then a fully densely connected convolutional network based on DenseNet is adopted to leverage features more efficiently and effectively for malware detection. Compared with the number of features in the original feature set, the number of features in the feature set obtained by the three levels of feature selection methods is reduced by about 97%, but the accuracy is only reduced by 0.45%, and the accuracy is more than 99% in a variety of machine learning methods. Moreover, we compare our detection method with different machine learning models, and the experimental results show that our method outperforms general machine learning models. We also compare the performance of our detection method with two state-of-the-art neural networks. The experimental results show that our detection model can greatly reduce the training cost and still achieve good detection performance, reaching an accuracy of 99.72%. In addition, we compare our detection method with other similar detection methods that also use multiple types of features. The results show that our detection method is superior to the comparison methods.

Publisher

Public Library of Science (PLoS)

Subject

Multidisciplinary

Reference81 articles.

1. Statcounter. Mobile Operating System Market Share Worldwide;. https://gs.statcounter.com/os-marketshare/mobile/worldwide.

2. Cranz A. There are over 3 billion active Android devices;. https://www.theverge.com/2021/5/18/22440813/android-devices-active-number-smartphones-google-2021.

3. Statista. Google Play: number of available apps as of Q1 2021;. https://www.statista.com/statistics/289418/number-of-available-apps-in-the-google-play-store-quarter.

4. Wang H, Liu Z, Liang J, Vallina-Rodriguez N, Guo Y, Li L, et al. Beyond google play: A large-scale comparative study of chinese android app markets. In: Proceedings of the Internet Measurement Conference 2018; 2018. p. 293–307.

5. of Tencent KSL. Android application security white paper 2018;. https://paper.seebug.org/953.

Cited by 5 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. A new adversarial malware detection method based on enhanced lightweight neural network;Computers & Security;2024-12

2. Dynamic Behaviour analysis and interpretation of Malware in Android devices using Ensemble Machine Learning;2024 3rd International Conference on Artificial Intelligence For Internet of Things (AIIoT);2024-05-03

3. Android malware detection framework based on sensitive opcodes and deep reinforcement learning;Journal of Intelligent & Fuzzy Systems;2024-04-18

4. Mitigating Malware Attacks using Machine Learning: A Review;2023 International Conference on Artificial Intelligence and Smart Communication (AISC);2023-01-27

5. Android Malware Detection by Correlated Real Permission Couples Using FP Growth Algorithm and Neural Networks;IEEE Access;2023

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3