Machine learning based hybrid behavior models for Android malware analysis
Journal
Proceedings - 2015 IEEE International Conference on Software Quality, Reliability and Security, QRS 2015
Pages
201-206
Date Issued
2015-08
Author(s)
Hsin-Yu Chuang
Abstract
Malware analysis on the Android platform has been an important issue as the platform became prevalent. The paper proposes a malware detection approach based on static analysis and machine learning techniques. By conducting SVM training on two different feature sets, malicious-preferred features and normal-preferred features, we built a hybrid-model classifier to improve the detection accuracy. With the consideration of normal behavior features, the ability of detecting unknown malwares can be improved. The experiments show that the accuracy is as high as 96.69% in predicting unknown applications. Further, the proposed approach can be applied to make confident decisions on labeling unknown applications. The experiment results show that the proposed hybrid model classifier can label 79.4% applications without false positive and false negative occurred in the labeling process. © 2015 IEEE.
Subjects
Android; classification; machine learning; malware detection; static analysis
SDGs
Other Subjects
Artificial intelligence; Classification (of information); Computer crime; Computer software selection and evaluation; Feature extraction; Learning systems; Malware; Software reliability; Static analysis; Android; Android platforms; Detection accuracy; False positive and false negatives; Machine learning techniques; Malware analysis; Malware detection; Preferred features; Android (operating system)
Type
conference paper
