<p>The widespread adoption of the Android system has sharply increased malicious Android applications, posing multifaceted threats to users. Given the problems of the single feature category and high computational overhead in current Android malware detection methods, this paper proposes a detection method based on feature fusion and an improved stacking integration model. First, seven types of numerical features and function call graphs (FCGs) are extracted from Android installation package files. Next, we apply five statistical methods to filter the numerical features, calculate four types of graph centrality indicators for risky API (application programming interface) nodes in the FCG, and concatenate them as the features of Android applications. These two categories of features correspond to the semantic and structural features of Android applications, respectively, which are static and do not need to be extracted with the help of deep learning techniques. Finally, this approach improves the stacking algorithm, constructing an ensemble classification model that considers the performance differences of the base classifier models and improves detection accuracy by weighting their outputs. The test results on the public dataset CICMalDroid2020 reveal that the method can achieve a detection accuracy of 98.16% and demonstrates the effectiveness of the feature fusion and integrated model.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Android malware detection based on feature fusion and the improved stacking ensemble model

  • Jiahao Zhang,
  • Zijiong Xu,
  • Zhi Xiong,
  • Lingru Cai

摘要

The widespread adoption of the Android system has sharply increased malicious Android applications, posing multifaceted threats to users. Given the problems of the single feature category and high computational overhead in current Android malware detection methods, this paper proposes a detection method based on feature fusion and an improved stacking integration model. First, seven types of numerical features and function call graphs (FCGs) are extracted from Android installation package files. Next, we apply five statistical methods to filter the numerical features, calculate four types of graph centrality indicators for risky API (application programming interface) nodes in the FCG, and concatenate them as the features of Android applications. These two categories of features correspond to the semantic and structural features of Android applications, respectively, which are static and do not need to be extracted with the help of deep learning techniques. Finally, this approach improves the stacking algorithm, constructing an ensemble classification model that considers the performance differences of the base classifier models and improves detection accuracy by weighting their outputs. The test results on the public dataset CICMalDroid2020 reveal that the method can achieve a detection accuracy of 98.16% and demonstrates the effectiveness of the feature fusion and integrated model.