Android malware concept drift using system calls: Detection, characterization and challenges

被引:16
|
作者
Guerra-Manzanares, Alejandro [1 ]
Luckner, Marcin [2 ]
Bahsi, Hayretdin [1 ]
机构
[1] Tallinn Univ Technol, Dept Software Sci, Tallinn, Estonia
[2] Warsaw Univ Technol, Fac Math & Informat Sci, Warsaw, Poland
关键词
Concept drift; Android malware; System calls; Mobile malware; Malware characterization; Malware detection; Malware evolution; Malware behavior; SELECTION; AWARE;
D O I
10.1016/j.eswa.2022.117200
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The majority of Android malware detection solutions have focused on the achievement of high performance in old and short snapshots of historical data, which makes them prone to lack the generalization and adaptation capabilities needed to discriminate effectively new malware trends in an extended time span. These approaches analyze the phenomenon from a stationary point of view, neglecting malware evolution and its degenerative impact on detection models as new data emerge, the so-called concept drift. This research proposes a novel method to detect and effectively address concept drift in Android malware detection and demonstrates the results in a seven-year-long data set. The proposed solution manages to keep high-performance metrics over a long period of time and minimizes model retraining efforts by using data sets belonging to short periods. Different timestamps are evaluated in the experimental setup and their impact on the detection performance is compared. Additionally, the characterization of concept drift in Android malware is performed by leveraging the inner workings of the proposed solution. In this regard, the discriminatory properties of the important features are analyzed at various time horizons.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] Detection of Android Malware Security on System Calls
    Chen Da
    Zhang Hongmei
    Zhang Xiangli
    [J]. PROCEEDINGS OF 2016 IEEE ADVANCED INFORMATION MANAGEMENT, COMMUNICATES, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (IMCEC 2016), 2016, : 974 - 978
  • [2] Evaluation of Android Malware Detection Based on System Calls
    Dimjasevic, Marko
    Atzeni, Simone
    Rakamaric, Zvonimir
    Ugrina, Ivo
    [J]. IWSPA'16: PROCEEDINGS OF THE 2016 ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS, 2016, : 1 - 8
  • [3] Sequencing System Calls for Effective Malware Detection in Android
    Ahsan-Ul-Haque, A. S. M.
    Hossain, Md. Shohrab
    Atiquzzaman, Mohammed
    [J]. 2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [4] The Concept Drift Problem in Android Malware Detection and Its Solution
    Hu, Donghui
    Ma, Zhongjin
    Zhang, Xiaotian
    Li, Peipei
    Ye, Dengpan
    Ling, Baohong
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2017,
  • [5] Concept drift and cross-device behavior: Challenges and implications for effective android malware detection
    Guerra-Manzanares, Alejandro
    Luckner, Marcin
    Bahsi, Hayretdin
    [J]. COMPUTERS & SECURITY, 2022, 120
  • [6] Identification of Android malware using refined system calls
    Deepa, K.
    Radhamani, G.
    Vinod, P.
    Shojafar, Mohammad
    Kumar, Neeraj
    Conti, Mauro
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2019, 31 (20):
  • [7] Efficient concept drift handling for batch android malware detection models
    Molina-Coronado, Borja
    Mori, Usue
    Mendiburu, Alexander
    Miguel-Alonso, Jose
    [J]. PERVASIVE AND MOBILE COMPUTING, 2023, 96
  • [8] STATIC DETECTION OF ANDROID MALWARE BY USING PERMISSIONS AND API CALLS
    Chan, Patrick P. K.
    Song, Wen-Kai
    [J]. PROCEEDINGS OF 2014 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS (ICMLC), VOL 1, 2014, : 82 - 87
  • [9] An Early Detection of Android Malware Using System Calls based Machine Learning Model
    Zhang, Xinrun
    Mathur, Akshay
    Zhao, Lei
    Rahmat, Safia
    Niyaz, Quamar
    Javaid, Ahmad
    Yang, Xiaoli
    [J]. PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [10] Android Malware Detection Based on System Calls Analysis and CNN Classification
    Abderrahmane, Abada
    Adnane, Guettaf
    Yacine, Challal
    Khireddine, Garri
    [J]. 2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE WORKSHOP (WCNCW), 2019,