Predicting Android malware combining permissions and API call sequences

被引:4
|
作者
Chen, Xin [1 ]
Yu, Haihua [1 ]
Yu, Dongjin [1 ]
Chen, Jie [1 ]
Sun, Xiaoxiao [1 ]
机构
[1] Hangzhou Dianzi Univ, Sch Comp Sci & Technol, Hangzhou 310018, Peoples R China
基金
中国国家自然科学基金;
关键词
Android malware; Malware detection; Permission; API call sequence; CNN; FRAMEWORK;
D O I
10.1007/s11219-022-09602-4
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Malware detection is an important task in software maintenance. It can effectively protect user information from the attack of malicious developers. Existing studies mainly focus on leveraging permission information and API call information to identify malware. However, many studies pay attention to the API call without considering the role of API call sequences. In this study, we propose a new method by combining both the permission information and the API call sequence information to distinguish malicious applications from benign applications. First, we extract features of permission and API call sequence with a decompiling tool. Then, one-hot encoding and Word2Vec are adopted to represent the permission feature and the API call sequence feature for each application, respectively. Based on this, we leverage Random Forest (RF) and Convolutional Neural Networks (CNN) to train a permission-based classifier and an API call sequence-based classifier, respectively. Finally, we design a linear strategy to combine the outputs of these two classifiers to predict the labels of newly arrived applications. By an evaluation with 15,198 malicious applications and 15,129 benign applications, our approach achieves 98.84% in terms of precision, 98.17% in terms of recall, 98.50% in terms of F1-score, and 98.52% in terms of accuracy on average, and outperforms the state-of-art method Malscan by 2.12%, 0.27%, 1.20%, and 1.24%, respectively. In addition, we demonstrate that the method combining two features achieves better performance than the methods based on a single feature.
引用
收藏
页码:655 / 685
页数:31
相关论文
共 50 条
  • [41] NATICUSdroid: A malware detection framework for Android using native and custom permissions
    Mathur, Akshay
    Podila, Laxmi Mounika
    Kulkarni, Keyur
    Niyaz, Quamar
    Javaid, Ahmad Y.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 58 (58)
  • [42] CTIMD: Cyber threat intelligence enhanced malware detection using API call sequences with parameters
    Chen, Tieming
    Zeng, Huan
    Lv, Mingqi
    Zhu, Tiantian
    COMPUTERS & SECURITY, 2024, 136
  • [43] A Longitudinal Study of Cryptographic API: A Decade of Android Malware
    Janovsky, Adam
    Maiorca, Davide
    Macko, Dominik
    Matyas, Vashek
    Giacinto, Giorgio
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 121 - 133
  • [44] Merging Permission and API Features for Android Malware Detection
    Qiao, Mengyu
    Sung, Andrew H.
    Liu, Qingzhong
    PROCEEDINGS 2016 5TH IIAI INTERNATIONAL CONGRESS ON ADVANCED APPLIED INFORMATICS IIAI-AAI 2016, 2016, : 566 - 571
  • [45] An accurate approach to discriminate android colluded malware from single app malware using permissions intelligence
    Mawoh, Roger Yiran
    Wacka, Joan Beri Ali
    Tchakounte, Franklin
    Fachkha, Claude
    Kolyang
    SCIENTIFIC REPORTS, 2025, 15 (01):
  • [46] NTPDroid: A Hybrid Android Malware Detector using Network Traffic and System Permissions
    Arora, Anshul
    Peddoju, Sateesh K.
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 808 - 813
  • [47] IPAnalyzer: A novel Android malware detection system using ranked Intents and Permissions
    Sharma, Yash
    Arora, Anshul
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (33) : 78957 - 79008
  • [48] Detecting Malware by Analyzing App Permissions on Android Platform: A Systematic Literature Review
    Ehsan, Adeel
    Catal, Cagatay
    Mishra, Alok
    SENSORS, 2022, 22 (20)
  • [49] AppPerm Analyzer: Malware Detection System Based on Android Permissions and Permission Groups
    Dogru, Ibrahim Alper
    Onder, Murat
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2020, 30 (03) : 427 - 450
  • [50] Dynamic Permissions based Android Malware Detection using Machine Learning Techniques
    Mahindru, Arvind
    Singh, Paramvir
    PROCEEDINGS OF THE 10TH INNOVATIONS IN SOFTWARE ENGINEERING CONFERENCE, 2017, : 202 - 210