Predicting Android malware combining permissions and API call sequences

被引:0
|
作者
Xin Chen
Haihua Yu
Dongjin Yu
Jie Chen
Xiaoxiao Sun
机构
[1] Hangzhou Dianzi University,School of Computer Science and Technology
来源
Software Quality Journal | 2023年 / 31卷
关键词
Android malware; Malware detection; Permission; API call sequence; CNN;
D O I
暂无
中图分类号
学科分类号
摘要
Malware detection is an important task in software maintenance. It can effectively protect user information from the attack of malicious developers. Existing studies mainly focus on leveraging permission information and API call information to identify malware. However, many studies pay attention to the API call without considering the role of API call sequences. In this study, we propose a new method by combining both the permission information and the API call sequence information to distinguish malicious applications from benign applications. First, we extract features of permission and API call sequence with a decompiling tool. Then, one-hot encoding and Word2Vec are adopted to represent the permission feature and the API call sequence feature for each application, respectively. Based on this, we leverage Random Forest (RF) and Convolutional Neural Networks (CNN) to train a permission-based classifier and an API call sequence-based classifier, respectively. Finally, we design a linear strategy to combine the outputs of these two classifiers to predict the labels of newly arrived applications. By an evaluation with 15,198 malicious applications and 15,129 benign applications, our approach achieves 98.84% in terms of precision, 98.17% in terms of recall, 98.50% in terms of F1-score, and 98.52% in terms of accuracy on average, and outperforms the state-of-art method Malscan by 2.12%, 0.27%, 1.20%, and 1.24%, respectively. In addition, we demonstrate that the method combining two features achieves better performance than the methods based on a single feature.
引用
收藏
页码:655 / 685
页数:30
相关论文
共 50 条
  • [31] Android Malware Detection Based on API Pairing
    Guan J.
    Liu H.
    Mao B.
    Jiang X.
    Xibei Gongye Daxue Xuebao/Journal of Northwestern Polytechnical University, 2020, 38 (05): : 965 - 970
  • [32] Using API Call Sequences for IoT Malware Classification Based on Convolutional Neural Networks
    Lin, Qianguang
    Li, Ni
    Qi, Qi
    Hu, Jiabin
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2021, 31 (04) : 587 - 612
  • [33] A New Malware Detection System Using Machine Learning Techniques for API Call Sequences
    Jerlin, M. Asha
    Marimuthu, K.
    JOURNAL OF APPLIED SECURITY RESEARCH, 2018, 13 (01) : 45 - 62
  • [34] MalAnalyser: An effective and efficient Windows malware detection method based on API call sequences
    Prachi
    Dabas, Namita
    Sharma, Prabha
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 230
  • [35] Malware Detection with Limited Supervised Information via Contrastive Learning on API Call Sequences
    Gao, Mohan
    Wu, Peng
    Pan, Li
    INFORMATION AND COMMUNICATIONS SECURITY, ICICS 2022, 2022, 13407 : 492 - 507
  • [36] Evolutionary Binary Classification using Cuckoo Search for Malware Perception in API Call Sequences
    Krishna, G. Bala
    Radha, V.
    Rao, K. Venu Gopala
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH (ICCIC), 2017, : 474 - 481
  • [37] Permissions-Based Detection of Android Malware Using Machine Learning
    Akbar, Fahad
    Hussain, Mehdi
    Mumtaz, Rafia
    Riaz, Qaiser
    Wahab, Ainuddin Wahid Abdul
    Jung, Ki-Hyun
    SYMMETRY-BASEL, 2022, 14 (04):
  • [38] DroidDelver: An Android Malware Detection System Using Deep Belief Network Based on API Call Blocks
    Hou, Shifu
    Saas, Aaron
    Ye, Yanfang
    Chen, Lifei
    WEB-AGE INFORMATION MANAGEMENT, 2016, 9998 : 54 - 66
  • [39] Droid Permission Miner: Mining Prominent Permissions for Android Malware Analysis
    Aswini, A. M.
    Vinod, P.
    2014 FIFTH INTERNATIONAL CONFERENCE ON THE APPLICATIONS OF DIGITAL INFORMATION AND WEB TECHNOLOGIES (ICADIWT), 2014, : 81 - 86
  • [40] Permissions-based Android malware detection using machine learning
    Alomar, Atheer
    AlJarullah, Asma
    Abu-Ghazalah, Sarah
    Neural Computing and Applications, 2025, 37 (06) : 5255 - 5270