期刊文献+

WEID:一种基于信息量差加权集成的Android恶意软件检测方法 被引量:3

WEID:A WEIGHTED ENSEMBLE METHOD BASED ON INFORMATION DIFFERENCE FOR ANDROID MALWARE DETECTION
下载PDF
导出
摘要 Android恶意软件的爆炸式增长给用户带来了严重的危害,而现有的应对方法普遍侧重于提升检测的正确率,较少考虑误报和漏检这两类误判情况。针对上述问题,提出一种基于信息量差加权集成的Android恶意软件检测方法。提取样本中权限和Intent这两类静态特征构造多组特征集;基于Stacking分层策略,将正负样本分类正确事件和分类错误事件的信息量差作为贡献度量,根据度量值指导基学习器加权集成,以获得最佳分类效果。实验结果表明,在由Drebin和Contagio构成的恶意样本集中,该方法的检测正确率在0.951~0.985之间,误报率和漏检率低至0.008和0.004,对比其他检测方法具有明显的优势。 The explosive growth of Android malware has hurt users seriously,and the existing coping methods emphasizes improving the accuracy while pays little attention to false positives and false negatives.Focusing on the problem,we propose a weighted ensemble method based on information difference for Android malware detection—WEID.WEID extracted the static features of permissions and intents from samples to construct five feature sets.Based on Stacking stratification strategy,WEID took the information difference of positive and negative sample correct and incorrect classification as the contribution metric of base-learners,and guided the weighted ensemble of the above learners according to the metric to obtain the optimal classification.Experimental results show that the detection accuracy of the proposed method in the malicious sample set consisting of Drebin and Contagio is capable of 0.951~0.985 with low false positive rate and false negative rate as low as 0.008 and 0.004,which is better than other detection methods.
作者 张高峰 鲍旭丹 刘敬 夏雪晗 郑利平 Zhang Gaofeng;Bao Xudan;Liu Jing;Xia Xuehan;Zheng Liping(School of Software,Hefei University of Technology,Hefei 230601,Anhui,China;School of Computer and Information,Hefei University of Technology,Hefei 230601,Anhui,China;Anhui Province Key Laboratory of Industrial Safety and Emergency Technology,Hefei University of Technology,Hefei 230601,Anhui,China)
出处 《计算机应用与软件》 北大核心 2022年第9期332-338,共7页 Computer Applications and Software
基金 国家自然科学基金项目(61972128) 国家自然科学基金青年基金项目(61702155) 安徽省自然科学基金面上项目(1808085MF176) 中央高校基本科研业务费专项资金项目(PA2019GDPK0071)。
关键词 Android恶意软件 静态特征 STACKING 信息量差 加权集成 Android malware Static features Stacking Information difference Weighted ensemble
  • 相关文献

参考文献6

二级参考文献165

  • 1耿新,周志华.Image Region Selection and Ensemble for Face Recognition[J].Journal of Computer Science & Technology,2006,21(1):116-125. 被引量:6
  • 2Motive Security Labs. Malware report--H2. 2014. http:/Pooletines.prisadigital.eom/MKT2015019837EN_2H2014.
  • 3Malware Report.pdf Mawston N. Strategy Analytics. Android shipped 1 billion smartphones worldwide in 2014. 2014. http://www.strategyanalyties.cora/ de fault.aspx?mod---reportabstraetviewer&a0= 10539.
  • 4Zhou Y, Jiang X. Dissecting android malware: Characterization and evolution. In: Prec. of the 2012 IEEE Syinp. on Security and Privacy (SP). 2012.95-109. [doi: 10.1109/SP.2012.16].
  • 5Felt AP, Firtifter M, Chin E, Hanna S, Wagner D. A survey of mobile malware in the wild. In: Proc. of the 1st ACM Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM 2011). 2011, 3-14. [doi: 10.1145/2046614.2046618].
  • 6La Polla M, Martinelli F, Sgandurra D. A survey on security for mobile devices. IEEE Communications Surveys & Tutorials, 2013,15(1): 446--471. [doi: 10.1109/SURV.2012.013012.00028].
  • 7Enck W. Defending users against smartphone apps: Techniques and future directions. In: Proc. of the 7th Int'1 Conf. (ICISS 2011). LNCS 7093, Springer-Verlag, 2011.49-70. [doi: 10.1007/978-3-642-25560-1_3].
  • 8Fledel Y, Shabtai A, Potashnik D, Elovici Y. Google Android: An updated security review. In: Proe. of the 2nd Int'1 ICST Conf. (MobiCASE 2010). Springer-Verlag, 2010. 401-414. [doi: 10.1007/978-3-642-29336-8_29].
  • 9Shabtai A, Fledel Y, Kanonov U, Elovicil Y, Dolev S. Google Android: A state-of-the-art review of security mechanisms, arXiv:0912. 5101 [cs.CR], 2009. http://arxiv.org/ftp/arxiv/papers/0912/0912.5101 .pdf.
  • 10Burns J. Developing secure mobile applications for Android. 2008. https://www.nccgroup.trust/globalassets/our-research/us/whitepapers/ isec securing_android apps .pdf.

共引文献161

同被引文献21

引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部