亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整的填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

MsDroid: Identifying Malicious Snippets for Android Malware Detection

计算机科学 恶意软件 人工智能 分类器(UML) 机器学习 Android恶意软件 情报检索 自然语言处理 计算机安全
作者
Yiling He,Yiping Liu,Lei Wu,Ziqi Yang,Kui Ren,Zhan Qin
出处
期刊:IEEE Transactions on Dependable and Secure Computing [Institute of Electrical and Electronics Engineers]
卷期号:20 (3): 2025-2039 被引量:13
标识
DOI:10.1109/tdsc.2022.3168285
摘要

Machine learning has shown promise for improving the accuracy of Android malware detection in the literature. However, it is challenging to (1) stay robust towards real-world scenarios and (2) provide interpretable explanations for experts to analyse. In this article, we propose MsDroid , an An droid malware detection system that makes decisions by identifying m alicious s nippets with interpretable explanations. We mimic a common practice of security analysts, i.e., filtering APIs before looking through each method, to focus on local snippets around sensitive APIs instead of the whole program. Each snippet is represented with a graph encoding both code attributes and domain knowledge and then classified by Graph Neural Network (GNN). The local perspective helps the GNN classifier to concentrate on code highly correlated with malicious behaviors, and the information contained in graphs benefit in better understanding of the behaviors. Hence, MsDroid is more robust and interpretable in nature. To identify malicious snippets, we present a semi-supervised learning approach that only requires app labeling. The key insight is that malicious snippets only exist in malwares and appear at least once in a malware. To make malicious snippets less opaque, we design an explanation mechanism to show the importance of control flows and to retrieve similarly implemented snippets from known malwares. A comprehensive comparison with 5 baseline methods is conducted on a dataset of more than 81K apps in 3 real-world scenarios, including zero-day , evolution , and obfuscation . The experimental results show that MsDroid is more robust than state-of-the-art systems in all cases, with 5.37% to 49.52% advantage in F1-score. Besides, we demonstrate that the provided explanations are effective and illustrate how the explanations facilitate malware analysis.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
Cristina2024完成签到,获得积分10
6秒前
7秒前
文献求助发布了新的文献求助10
12秒前
qqq完成签到,获得积分10
1分钟前
害羞迎南发布了新的文献求助200
3分钟前
3分钟前
3分钟前
害羞迎南完成签到,获得积分0
4分钟前
dolphin完成签到 ,获得积分10
4分钟前
NexusExplorer应助叔叔的哥哥采纳,获得10
5分钟前
lanxinyue应助科研通管家采纳,获得100
5分钟前
迷你的靖雁完成签到,获得积分10
5分钟前
5分钟前
5分钟前
wyx完成签到,获得积分10
5分钟前
yxm完成签到 ,获得积分10
6分钟前
6分钟前
6分钟前
gc完成签到 ,获得积分10
6分钟前
魏白晴完成签到,获得积分10
7分钟前
李爱国应助科研通管家采纳,获得10
7分钟前
所所应助顺利的绿真采纳,获得10
7分钟前
hongxuezhi完成签到,获得积分10
8分钟前
碧蓝问玉完成签到 ,获得积分10
8分钟前
yihuifa完成签到 ,获得积分10
9分钟前
9分钟前
9分钟前
Chavin完成签到 ,获得积分10
9分钟前
9分钟前
9分钟前
10分钟前
liuzhh79发布了新的文献求助10
10分钟前
知鸢完成签到 ,获得积分10
10分钟前
liuzhh79完成签到,获得积分10
11分钟前
叔叔的哥哥完成签到,获得积分20
11分钟前
evanevanus完成签到,获得积分10
13分钟前
机灵的爆米花完成签到 ,获得积分10
13分钟前
13分钟前
13分钟前
Akim应助科研通管家采纳,获得10
13分钟前
高分求助中
Biology and Ecology of Atlantic Cod 1500
LNG地下式貯槽指針(JGA指-107-19)(Recommended practice for LNG inground storage) 1000
Second Language Writing (2nd Edition) by Ken Hyland, 2019 1000
Generalized Linear Mixed Models 第二版 1000
rhetoric, logic and argumentation: a guide to student writers 1000
QMS18Ed2 | process management. 2nd ed 1000
Operative Techniques in Pediatric Orthopaedic Surgery 510
热门求助领域 (近24小时)
化学 医学 材料科学 生物 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 物理化学 催化作用 免疫学 细胞生物学 电极
热门帖子
关注 科研通微信公众号,转发送积分 2922099
求助须知:如何正确求助?哪些是违规求助? 2565567
关于积分的说明 6937202
捐赠科研通 2222174
什么是DOI,文献DOI怎么找? 1181371
版权声明 588852
科研通“疑难数据库(出版商)”最低求助积分说明 577971