期刊论文详细信息
Symmetry
Android Malware Detection Using TCN with Bytecode Image
Chao Ding1  Wenhui Zhang1  Nurbol Luktarhan1  Bei Lu1 
[1] College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China;
关键词: Android malware detection;    TCN;    XML file;    data section;    bytecode image;   
DOI  :  10.3390/sym13071107
来源: DOAJ
【 摘 要 】

With the rapid increase in the number of Android malware, the image-based analysis method has become an effective way to defend against symmetric encryption and confusing malware. At present, the existing Android malware bytecode image detection method, based on a convolution neural network (CNN), relies on a single DEX file feature and requires a large amount of computation. To solve these problems, we combine the visual features of the XML file with the data section of the DEX file for the first time, and propose a new Android malware detection model, based on a temporal convolution network (TCN). First, four gray-scale image datasets with four different combinations of texture features are created by combining XML files and DEX files. Then the image size is unified and input to the designed neural network with three different convolution methods for experimental validation. The experimental results show that adding XML files is beneficial for Android malware detection. The detection accuracy of the TCN model is 95.44%, precision is 95.45%, recall rate is 95.45%, and F1-Score is 95.44%. Compared with other methods based on the traditional CNN model or lightweight MobileNetV2 model, the method proposed in this paper, based on the TCN model, can effectively utilize bytecode image sequence features, improve the accuracy of detecting Android malware and reduce its computation.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:0次