Deakin University
Browse

HeterSupervise: package-level android malware analysis based on heterogeneous graph

conference contribution
posted on 2020-01-01, 00:00 authored by J Jiang, Z Liu, M Yu, Gang LiGang Li, S Li, C Liu, W Huang
In order to evade the detection of mobile security products, Android malware has become more and more complex, meanwhile, new variants grow rapidly. Facing variant malware, traditional detection methods ignore the complex interrelationships between Apps, and the purity of the detection is insufficient, hence cannot accurately and efficiently detect their complex behaviors, even difficult to detect. To combat the evolving Android malware attacks, we proposed method HeterSupervise which can analyze Android malware from an essential perspective. Firstly, We extracting various static and dynamic features from Apps using HSandroguard. To model different types of entities (i.e., code regions, sensitive API, package, signature) and rich relations among them, we present a heterogeneous graph for modeling. Secondly, in order to get the feature representation of each node, we design the HGN-embedding method to obtain the embedding of nodes belong to different types. Thirdly, we build HG-CNN classifiers based on various typical CNNs to detect unknown Android Apps. We integrate the above methods as a system Heter-Supervisor. Comprehensive experiments show that HeterSupervisor achieves more than 97% accuracy, and outperforms the state-of-the-art methods in efficiency with 60% improvement.

History

Pagination

328-335

Location

Yanuca Island, Cuvu, Fiji

Start date

2020-12-14

End date

2020-12-16

ISBN-13

9781728176499

Language

eng

Publication classification

E1 Full written paper - refereed

Editor/Contributor(s)

[Unknown]

Title of proceedings

Proceedings of the 2020 IEEE 22nd International Conference on High Performance Computing and Communications, IEEE 18th International Conference on Smart City and IEEE 6th International Conference on Data Science and Systems, HPCC-SmartCity-DSS

Event

IEEE 22nd International Conference on High Performance Computing and Communications; IEEE 18th International Conference on Smart City; IEEE 6th International Conference on Data Science and Systems (HPCC/SmartCity/DSS) (2020 : Yanuca Island, Cuvu, Fiji)

Publisher

IEEE

Place of publication

Piscataway, N.J.

Usage metrics

    Research Publications

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC