An effective attention and residual network for malware detection

Author:

Gu Wei1,Xing Hongyan1ORCID,Hou Tianhao1

Affiliation:

1. School of Electronics and Information Engineering Nanjing University of Information Science and Technology Nanjing China

Abstract

AbstractDue to its open source and large user base, Android has emerged as the most popular operating system. Android's popularity and openness have made it a prime target for malicious attackers. Permissions have received great attention from researchers because of their effectiveness in restricting applications’ access to sensitive resources. However, existing malware detection methods based on permissions are easily bypassed by inter‐application resource access. To address these issues, we combine inter‐application resource access‐related intent features with permission features. Besides, we designed a customized convolutional neural network using two squeeze‐and‐excitation blocks to learn the inherent relationships between multi‐type features. The two basic SE blocks perform squeezing operations based on average pooling and max pooling, respectively, to compute channel‐wise attention from multiple perspectives. We designed a series of experiments based on real‐world samples to evaluate the efficacy of the proposed framework. Empirical results demonstrate that our framework outperforms state‐of‐the‐art methods, achieving an accuracy of 96.29%, precision of 97.52%, recall of 94.63%, F1‐score of 96.06% and MCC of 92.60%. These promising experimental results consistently demonstrate that AMERDroid is an effective approach for Android malware detection.

Funder

National Natural Science Foundation of China

National Key Research and Development Program of China

Publisher

Institution of Engineering and Technology (IET)

Reference51 articles.

1. A longitudinal study of application structure and behaviors in android;Cai H.;IEEE Trans. Software Eng.,2020

2. Quick heal threat report Q3‐2020.https://www.quickheal.com. Accessed 28 Dec. 2020

3. Smartphone Market Share.https://www.idc.com/promo/smartphone‐market‐share. Accessed 29 Dec. 2020

4. MADAM: Effective and Efficient Behavior-based Android Malware Detection and Prevention

5. Aye T.D.N. Justin S.B.G. Yarzar S.W. Jonathan P.:A review on the effectiveness of dimensional reduction with computational forensics: An application on malware analysis. arXiv: 2301.06031 (2023)

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3