A Multiclass Detection System for Android Malicious Apps Based on Color Image Features

被引:10
|
作者
Zhang, Hua [1 ]
Qin, Jiawei [1 ]
Zhang, Boan [1 ]
Yan, Hanbing [2 ]
Guo, Jing [2 ]
Gao, Fei [1 ]
Wang, Senmiao [1 ]
Hu, Yangye [1 ]
机构
[1] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
[2] Coordinat Ctr China, Natl Comp Network Emergency Response Tech Team, Beijing, Peoples R China
来源
WIRELESS COMMUNICATIONS & MOBILE COMPUTING | 2020年 / 2020卷
基金
国家重点研发计划;
关键词
Classification (of information) - Visualization - Android (operating system) - Feature extraction - Deep learning;
D O I
10.1155/2020/8882295
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The visual recognition of Android malicious applications (Apps) is mainly focused on the binary classification using grayscale images, while the multiclassification of malicious App families is rarely studied. If we can visualize the Android malicious Apps as color images, we will get more features than using grayscale images. In this paper, a method of color visualization for Android Apps is proposed and implemented. Based on this, combined with deep learning models, a multiclassifier for the Android malicious App families is implemented, which can classify 10 common malicious App families. In order to better understand the behavioral characteristics of malicious Apps, we conduct a comprehensive manual analysis for a large number of malicious Apps and summarize 1695 malicious behavior characteristics as customized features. Compared with the App classifier based on the grayscale visualization method, it is verified that the classifier using the color visualization method can achieve better classification results. We use four types of Android App features: classes.dex file, sets of class names, APIs, and customized features as input for App visualization. According to the experimental results, we find out that using the customized features as the color visualization input features can achieve the highest detection accuracy rate, which is 96% in the ten malicious families.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] Network-based detection of Android malicious apps
    Shree Garg
    Sateesh K. Peddoju
    Anil K. Sarje
    International Journal of Information Security, 2017, 16 : 385 - 400
  • [2] Network-based detection of Android malicious apps
    Garg, Shree
    Peddoju, Sateesh K.
    Sarje, Anil K.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2017, 16 (04) : 385 - 400
  • [3] Detection of Android Malicious Apps Based on the Sensitive Behaviors
    Quan, Daiyong
    Zhai, Lidong
    Yang, Fan
    Wang, Peng
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 877 - 883
  • [4] A Survey on the Detection of Android Malicious Apps
    Sahay, Sanjay K.
    Sharma, Ashu
    ADVANCES IN COMPUTER COMMUNICATION AND COMPUTATIONAL SCIENCES, IC4S 2018, 2019, 924 : 437 - 446
  • [5] MOWAD: Automation-based Detection of Malicious OfferWall Android Apps
    Zhang, Shaodong
    Feng, Dong
    Li, Qi
    PROCEEDINGS OF 2017 2ND INTERNATIONAL CONFERENCE ON COMMUNICATION AND INFORMATION SYSTEMS (ICCIS 2017), 2015, : 239 - 243
  • [6] Malicious Android Application Detection Based on Composite Features
    Xiao, Jingxu
    Xu, Kaiyong
    Duan, Jialiang
    PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND APPLICATION ENGINEERING (CSAE2019), 2019,
  • [7] A MACHINE LEARNING APPROACH TO THE DETECTION AND ANALYSIS OF ANDROID MALICIOUS APPS
    Shibija, K.
    Raymond, Joseph, V
    2018 INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND INFORMATICS (ICCCI), 2018,
  • [8] Detection of malicious apps in Android OS by using mobile network
    Shelke, Chetan J.
    Karde, Pravin
    Thakre, V. M.
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ELECTRONICS, INFORMATION & COMMUNICATION TECHNOLOGY (RTEICT), 2017, : 417 - 420
  • [9] Real-time Detection of Malicious Behavior in Android Apps
    Ni, Zhenyu
    Yang, Ming
    Ling, Zhen
    Wu, Jia-nan
    Luo, Junzhou
    2016 FOURTH INTERNATIONAL CONFERENCE ON ADVANCED CLOUD AND BIG DATA (CBD 2016), 2016, : 221 - 227
  • [10] Identifying malicious Android apps using permissions and system events
    Han, Hongmu
    Li, Ruixuan
    Gu, Xiwu
    INTERNATIONAL JOURNAL OF EMBEDDED SYSTEMS, 2016, 8 (01) : 46 - 58