Android malware concept drift using system calls: Detection, characterization and challenges

被引:16
|
作者
Guerra-Manzanares, Alejandro [1 ]
Luckner, Marcin [2 ]
Bahsi, Hayretdin [1 ]
机构
[1] Tallinn Univ Technol, Dept Software Sci, Tallinn, Estonia
[2] Warsaw Univ Technol, Fac Math & Informat Sci, Warsaw, Poland
关键词
Concept drift; Android malware; System calls; Mobile malware; Malware characterization; Malware detection; Malware evolution; Malware behavior; SELECTION; AWARE;
D O I
10.1016/j.eswa.2022.117200
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The majority of Android malware detection solutions have focused on the achievement of high performance in old and short snapshots of historical data, which makes them prone to lack the generalization and adaptation capabilities needed to discriminate effectively new malware trends in an extended time span. These approaches analyze the phenomenon from a stationary point of view, neglecting malware evolution and its degenerative impact on detection models as new data emerge, the so-called concept drift. This research proposes a novel method to detect and effectively address concept drift in Android malware detection and demonstrates the results in a seven-year-long data set. The proposed solution manages to keep high-performance metrics over a long period of time and minimizes model retraining efforts by using data sets belonging to short periods. Different timestamps are evaluated in the experimental setup and their impact on the detection performance is compared. Additionally, the characterization of concept drift in Android malware is performed by leveraging the inner workings of the proposed solution. In this regard, the discriminatory properties of the important features are analyzed at various time horizons.
引用
收藏
页数:19
相关论文
共 50 条
  • [21] On the relativity of time: Implications and challenges of data drift on long-term effective android malware detection
    Guerra-Manzanares, Alejandro
    Bahsi, Hayretdin
    [J]. COMPUTERS & SECURITY, 2022, 122
  • [22] Android Malware Detection Method Based on Permission Complement and API Calls
    Yang, Jiyun
    Tang, Jiang
    Yan, Ran
    Xiang, Tao
    [J]. CHINESE JOURNAL OF ELECTRONICS, 2022, 31 (04) : 773 - 785
  • [23] URefFlow: A Unified Android Malware Detection Model Based on Reflective Calls
    Liu, Chao
    Li, Jianan
    Yu, Min
    Li, Gang
    Luo, Bo
    Chen, Kai
    Jiang, Jianguo
    Huang, Weiqing
    [J]. 2018 IEEE 37TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2018,
  • [24] DroidMat: Android Malware Detection through Manifest and API Calls Tracing
    Wu, Dong-Jie
    Mao, Ching-Hao
    Wei, Te-En
    Lee, Hahn-Ming
    Wu, Kuo-Ping
    [J]. PROCEEDINGS OF THE 2012 SEVENTH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS 2012), 2012, : 62 - 69
  • [25] Android Malware Detection Using API Calls: A Comparison of Feature Selection and Machine Learning Models
    Muzaffar, Ali
    Hassen, Hani Ragab
    Lones, Michael A.
    Zantout, Hind
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON APPLIED CYBER SECURITY (ACS) 2021, 2022, 378 : 3 - 12
  • [26] Android Malware Detection based on Useful API Calls and Machine Learning
    Jung, Jaemin
    Kim, Hyunjin
    Shin, Dongjin
    Lee, Myeonggeon
    Lee, Hyunjae
    Cho, Seong-je
    Suh, Kyoungwon
    [J]. 2018 IEEE FIRST INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND KNOWLEDGE ENGINEERING (AIKE), 2018, : 175 - 178
  • [27] Android Malware Detection Method Based on Permission Complement and API Calls
    YANG Jiyun
    TANG Jiang
    YAN Ran
    XIANG Tao
    [J]. Chinese Journal of Electronics, 2022, (04) : 773 - 785
  • [28] Android Malware Detection Using BERT
    Souani, Badr
    Khanfir, Ahmed
    Bartel, Alexandre
    Allix, Kevin
    Le Traon, Yves
    [J]. APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2022, 2022, 13285 : 575 - 591
  • [29] Droid Detector:Android Malware Characterization and Detection Using Deep Learning
    Zhenlong Yuan
    Yongqiang Lu
    Yibo Xue
    [J]. Tsinghua Science and Technology, 2016, 21 (01) : 114 - 123
  • [30] Malware detection model based on classifying system calls and code attributes: A proof of concept
    Saleh, Malik F.
    [J]. International Journal of Electronic Security and Digital Forensics, 2019, 11 (02): : 183 - 193