Employing combined spatial and frequency domain image features for machine learning-based malware detection

Author:

Bashar Abul

Abstract

<p>The ubiquitous adoption of Android devices has unfortunately brought a surge in malware threats, compromising user data, privacy concerns, and financial and device integrity, to name a few. To combat this, numerous efforts have explored automated botnet detection mechanisms, with anomaly-based approaches leveraging machine learning (ML) gaining attraction due to their signature-agnostic nature. However, the problem lies in devising accurate ML models which capture the ever evolving landscape of malwares by effectively leveraging all the possible features from Android application packages (APKs).This paper delved into this domain by proposing, implementing, and evaluating an image-based Android malware detection (AMD) framework that harnessed the power of feature hybridization. The core idea of this framework was the conversion of text-based data extracted from Android APKs into grayscale images. The novelty aspect of this work lied in the unique image feature extraction strategies and their subsequent hybridization to achieve accurate malware classification using ML models. More specifically, four distinct feature extraction methodologies, namely, Texture and histogram of oriented gradients (HOG) from spatial domain, and discrete wavelet transform (DWT) and Gabor from the frequency domain were employed to hybridize the features for improved malware identification. To this end, three image-based datasets, namely, Dex, Manifest, and Composite, derived from the information security centre of excellence (ISCX) Android Malware dataset, were leveraged to evaluate the optimal data source for botnet classification. Popular ML classifiers, including naive Bayes (NB), multilayer perceptron (MLP), support vector machine (SVM), and random forest (RF), were employed for the classification task. The experimental results demonstrated the efficacy of the proposed framework, achieving a peak classification accuracy of 93.03% and recall of 97.1% for the RF classifier using the Manifest dataset and a combination of Texture and HOG features. These findings validate the proof-of-concept and provide valuable insights for researchers exploring ML/deep learning (DL) approaches in the domain of AMD.</p>

Publisher

American Institute of Mathematical Sciences (AIMS)

Reference45 articles.

1. T. Shishkova, A. Kivva, Mobile Malware Evolution 2021, 2021. Available from: https://securelist.com/mobile-malware-evolution-2021/105876.

2. AppBrain, Number of Android Apps on Google Play, 2024. Available from: https://www.appbrain.com/stats/number-of-android-apps.

3. McAfee, McAfee Mobile Threat Report, 2021. Available from: https://www.mcafee.com/content/dam/global/infographics/McAfeeMobileThreatReport2021.pdf.

4. J. Senanayake, H. Kalutarage, M. O. Al-Kadri, Android mobile malware detection using machine learning: A systematic review, Electronics, 10 (2021), 1606. https://doi.org/10.3390/electronics10131606

5. S. Y. Yerima, A. Bashar, A novel android botnet detection system using image-based and manifest file features, Electronics, 11 (2022), 486. https://doi.org/10.3390/electronics11030486

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3