...
首页> 外文期刊>Computer networks >Mining nested flow of dominant APIs for detecting android malware
【24h】

Mining nested flow of dominant APIs for detecting android malware

机译:挖掘主要API的嵌套流以检测android恶意软件

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

According to the Kaspersky Lab threat report, mobile malware attacks almost doubled in 2018. A study conducted in 2018 by Accenture found malware attacks to be the most expensive to resolve. Android Operating System (OS) is the most dominating platform on mobile devices. This makes Android OS susceptible to malware attacks. We need to develop new techniques and methods to stop this influx of malware attacks. In this paper, we propose a novel technique named DroidDomTree that mines the dominance tree of API (Application programming interface) calls to find similar patterns in Android applications for detecting malware. Dominance is a transitive relation. A dominance tree of API calls highlights a strong flow of path and identifies the nesting structure of APIs and hence emphasizes the importance of certain APIs in an application. It also helps in finding modules and their interaction in an application. If a malicious module is embedded in an application, then this provides strong evidence that the application contains malware. We use these properties and develop a nested model of the dominance tree of API calls and a new scheme for assigning weights to each node in the dominance tree for efficient feature selection. During 10-fold cross-validation, with eight different classifiers using real malware Android applications, DroidDomTree achieved detection rates in the range of 98.1%-99.3% and false positive rates in the range of 1.7%-0.4%. (C) 2019 Elsevier B.V. All rights reserved.
机译:根据卡巴斯基实验室威胁报告,移动恶意软件攻击在2018年几乎翻了一番。埃森哲(Accenture)在2018年进行的一项研究发现,恶意软件攻击是最昂贵的解决方案。 Android操作系统(OS)是移动设备上最主要的平台。这使得Android操作系统容易受到恶意软件攻击。我们需要开发新技术和方法来阻止这种恶意软件攻击的涌入。在本文中,我们提出了一种名为DroidDomTree的新技术,该技术可挖掘API(应用程序编程接口)调用的优势树,以在Android应用程序中找到类似的模式以检测恶意软件。支配地位是传递关系。 API调用的优势树突出显示了强大的路径流,并标识了API的嵌套结构,因此强调了某些API在应用程序中的重要性。它还有助于在应用程序中查找模块及其交互。如果在应用程序中嵌入了恶意模块,则可以提供有力的证据证明该应用程序包含恶意软件。我们使用这些属性并开发API调用优势树的嵌套模型,以及为权重树中的每个节点分配权重以进行有效特征选择的新方案。在十次交叉验证中,使用八个真正的恶意软件Android应用程序进行了不同的分类,DroidDomTree的检出率在98.1%-99.3%的范围内,假阳性率在1.7%-0.4%的范围内。 (C)2019 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号