期刊论文详细信息
IEEE Access
FAMD: A Fast Multifeature Android Malware Detection Framework, Design, and Implementation
Nannan Xie1  Xiaoqiang Di1  Hongpeng Bai1  Qing Ye1 
[1] School of Computer Science and Technology, Changchun University of Science and Technology, Changchun, China;
关键词: Android malware;    CatBoost;    Dalvik opcode;    malware detection;   
DOI  :  10.1109/ACCESS.2020.3033026
来源: DOAJ
【 摘 要 】

With Android's dominant position within the current smartphone OS, increasing number of malware applications pose a great threat to user privacy and security. Classification algorithms that use a single feature usually have weak detection performance. Although the use of multiple features can improve the detection effect, increasing the number of features increases the requirements of the operating environment and consumes more time. We propose a fast Android malware detection framework based on the combination of multiple features: FAMD (Fast Android Malware Detector). First, we extracted permissions and Dalvik opcode sequences from samples to construct the original feature set. Second, the Dalvik opcodes are preprocessed with the N-Gram technique, and the FCBF (Fast Correlation-Based Filter) algorithm based on symmetrical uncertainty is employed to reduce feature dimensionality. Finally, the dimensionality-reduced features are input into the CatBoost classifier for malware detection and family classification. The dataset DS-1, which we collected, and the baseline dataset Drebin were used in the experiment. The results show that the combined features can effectively improve the detection accuracy of malware that can reach 97.40% on Drebin dataset, and the malware family classification accuracy can achieve 97.38%. Compared with other state-of-the-art works, our framework achieves higher accuracy and lower time consumption.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:0次