<p>The rapid growth of the Android application market has been accompanied by a growth in the number of types of malware that use permissions, components and application metadata to filter out malware. Traditional static analysis techniques tend to have problems in dealing with class imbalance, sparse family labels, and overfitting in a multi-class case. This work presents an improved static-analysis machine learning approach based on Android malware analysis that works at the type and family level. Building on permission-centric techniques, the framework is based on activity-level and component-level features extracted from the Android manifest that enhance the discriminativeness of the framework and keep it interpretable. The data set consists of 429 applications that were consolidated into 4 types of malware and 14 families. To control the severe imbalance, conservative resampling and stratified evaluation are implemented. For the type level detection, a stacking ensemble made of Random Forest, Gradient Boosting and Logistic Regression with 92.25% test precision achieves stable cross-validation performance. For the purpose of family-level classification, an XGBoost model on features only derived from the manifest has 92.86% accuracy and a macro F1 score of 90.48%. Sensitive permissions and advertising-related components are important indicators in various families, according to feature importance analysis. The results have shown how well-engineered static features coupled with overfitting-aware ensemble design can give robust results of multi-class malware classification in the absence of dynamic traces. Future work will combine the modelling of dynamic behaviour with federated learning and Explainable Artificial Intelligence to develop additional resilience from obfuscation and runtime-evasive threats.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhanced static analysis framework for multi-class Android malware detection using machine learning

  • Hemraj Shobharam Lamkuche,
  • Mannat Pal

摘要

The rapid growth of the Android application market has been accompanied by a growth in the number of types of malware that use permissions, components and application metadata to filter out malware. Traditional static analysis techniques tend to have problems in dealing with class imbalance, sparse family labels, and overfitting in a multi-class case. This work presents an improved static-analysis machine learning approach based on Android malware analysis that works at the type and family level. Building on permission-centric techniques, the framework is based on activity-level and component-level features extracted from the Android manifest that enhance the discriminativeness of the framework and keep it interpretable. The data set consists of 429 applications that were consolidated into 4 types of malware and 14 families. To control the severe imbalance, conservative resampling and stratified evaluation are implemented. For the type level detection, a stacking ensemble made of Random Forest, Gradient Boosting and Logistic Regression with 92.25% test precision achieves stable cross-validation performance. For the purpose of family-level classification, an XGBoost model on features only derived from the manifest has 92.86% accuracy and a macro F1 score of 90.48%. Sensitive permissions and advertising-related components are important indicators in various families, according to feature importance analysis. The results have shown how well-engineered static features coupled with overfitting-aware ensemble design can give robust results of multi-class malware classification in the absence of dynamic traces. Future work will combine the modelling of dynamic behaviour with federated learning and Explainable Artificial Intelligence to develop additional resilience from obfuscation and runtime-evasive threats.