A Lightweight Android Malware Classifier Using Novel Feature Selection Methods

Author:

Salah AhmadORCID,Shalabi Eman,Khedr WalidORCID

Abstract

Smartphones and mobile tablets play significant roles in daily life and have led to an increase in the number of users of this technology. The rising number of mobile device end-users has resulted in the generation of malware by hackers. Thus, mobile devices are becoming vulnerable to malware. Machine learning plays an important role in the detection of mobile malware applications. In this study, we focus on static analysis for Android malware detection. The ultimate goal of this research is to find out the symmetric features across the malware Android application to easily detect them. Many state-of-the-art methods focus on extracting asymmetric patterns of the category of features, e.g., application permissions to distinguish the malware application from the benign application. In this work, we propose a compromise by considering different types of static features and select the most important features that affect the detection process. These features represent the symmetric pattern to be used for the classification task. Inspired by TF-IDF, we propose a novel method of feature selection. Moreover, we propose a new method for merging the Android application URLs into a single feature called the URL_score. Several linear machine learning classifiers are utilized to evaluate the proposed method. The proposed methods significantly reduce the feature space, i.e., the symmetric pattern, of the Android application dataset and the memory size of the final model. In addition, the proposed model achieves the highest reported accuracy for the Drebin dataset to date. Based on the evaluation results, the linear support vector machine achieves an accuracy of 99%.

Publisher

MDPI AG

Subject

Physics and Astronomy (miscellaneous),General Mathematics,Chemistry (miscellaneous),Computer Science (miscellaneous)

Reference42 articles.

1. Android OS Market Share of Smartphone Sales to End Usershttps://www.statista.com/statistics/216420/global-market-share-forecast-of-smartphone-operating-systems/

2. An Autonomous Host-Based Intrusion Detection System for Android Mobile Devices

3. Attack Detection Application with Attack Tree for Mobile System using Log Analysis

4. A Survey of Android Mobile Phone Authentication Schemes

Cited by 35 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. VolMemDroid—Investigating android malware insights with volatile memory artifacts;Expert Systems with Applications;2024-11

2. Meta-Learning for Multi-Family Android Malware Classification;ACM Transactions on Software Engineering and Methodology;2024-08-26

3. FSSDroid: Feature subset selection for Android malware detection;World Wide Web;2024-07-16

4. Identifying Malware using Machine Learning Ensemble Model;2024 International Conference on Advances in Computing, Communication and Applied Informatics (ACCAI);2024-05-09

5. On Static Android Malware Detection and Analysis: A Systematic Review;Lecture Notes in Networks and Systems;2024

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3