Improving Accuracy of Android Malware Detection with Lightweight Contextual Awareness

被引:24
|
作者
Allen, Joey [1 ]
Landen, Matthew [1 ]
Chaba, Sanya [1 ]
Ji, Yang [1 ]
Chung, Simon Pak Ho [1 ]
Lee, Wenke [1 ]
机构
[1] Georgia Inst Technol, Atlanta, GA 30332 USA
关键词
Malware detection; Android Security;
D O I
10.1145/3274694.3274744
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In Android malware detection, recent work has shown that using contextual information of sensitive API invocation in the modeling of applications is able to improve the classification accuracy. However, the improvement brought by this context-awareness varies depending on how this information is used in the modeling. In this paper, we perform a comprehensive study on the effectiveness of using the contextual information in prior state-of-the-art detection systems. We find that this information has been "over-used" such that a large amount of non-essential metadata built into the models weakens the generalizability and longevity of the model, thus finally affects the detection accuracy. On the other hand, we find that the entrypoint of API invocation has the strongest impact on the classification correctness, which can further improve the accuracy if being properly captured. Based on this finding, we design and implement a lightweight, circumstance-aware detection system, named "PIKADROID" that only uses the API invocation and its entrypoint in the modeling. For extracting the meaningful entrypoints, PIKADROID applies a set of static analysis techniques to extract and sanitize the reachable entrypoints of a sensitive API, then constructs a frequency model for classification decision. In the evaluation, we show that this slim model significantly improves the detection accuracy on a data set of 23,631 applications by achieving an f-score of 97.41%, while maintaining a false positive rating of 0.96%.
引用
收藏
页码:210 / 221
页数:12
相关论文
共 50 条
  • [1] A Lightweight On-Device Detection Method for Android Malware
    Yuan, Wei
    Jiang, Yuan
    Li, Heng
    Cai, Minghui
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2021, 51 (09): : 5600 - 5611
  • [2] PAIRED: An Explainable Lightweight Android Malware Detection System
    Alani, Mohammed M.
    Awad, Ali Ismail
    IEEE ACCESS, 2022, 10 : 73214 - 73228
  • [3] TinyDroid: A Lightweight and Efficient Model for Android Malware Detection and Classification
    Chen, Tieming
    Mao, Qingyu
    Yang, Yimin
    Lv, Mingqi
    Zhu, Jianming
    MOBILE INFORMATION SYSTEMS, 2018, 2018
  • [4] A Lightweight Android Malware Detection Framework Based on Knowledge Distillation
    Zhi, Yongbo
    Xi, Ning
    Liu, Yuanqing
    Hui, Honglei
    NETWORK AND SYSTEM SECURITY, NSS 2021, 2021, 13041 : 116 - 130
  • [5] A Lightweight Network-based Android Malware Detection System
    Sanz, Igor Jochem
    Lopez, Martin Andreoni
    Viegas, Eduardo Kugler
    Sanches, Vinicius Rodrigues
    2020 IFIP NETWORKING CONFERENCE AND WORKSHOPS (NETWORKING), 2020, : 695 - 703
  • [6] An Android Malware Detection Method Using Better API Contextual Information
    Yang, Hongyu
    Wang, Youwei
    Zhang, Liang
    Hu, Ze
    Jiang, Laiwei
    Cheng, Xiang
    INFORMATION SECURITY AND CRYPTOLOGY, INSCRYPT 2023, PT II, 2024, 14527 : 24 - 36
  • [7] A lightweight deep learning-based android malware detection framework
    Ma, Runze
    Yin, Shangnan
    Feng, Xia
    Zhu, Huijuan
    Sheng, Victor S.
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 255
  • [8] Lightweight versus obfuscation-resilient malware detection in android applications
    Aghamohammadi, Ali
    Faghih, Fathiyeh
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2020, 16 (02) : 125 - 139
  • [9] Android Malware Detection Technology Based on Lightweight Convolutional Neural Networks
    Ye, Genchao
    Zhang, Jian
    Li, Huanzhou
    Tang, Zhangguo
    Lv, Tianzi
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [10] Securing Android IoT devices with GuardDroid transparent and lightweight malware detection
    Wajahat, Ahsan
    He, Jingsha
    Zhu, Nafei
    Mahmood, Tariq
    Nazir, Ahsan
    Ullah, Faheem
    Qureshi, Sirajuddin
    Dev, Soumyabrata
    AIN SHAMS ENGINEERING JOURNAL, 2024, 15 (05)