HeterSupervise: package-level android malware analysis based on heterogeneous graph
conference contribution
posted on 2020-01-01, 00:00authored byJ Jiang, Z Liu, M Yu, Gang LiGang Li, S Li, C Liu, W Huang
In order to evade the detection of mobile security products, Android malware has become more and more complex, meanwhile, new variants grow rapidly. Facing variant malware, traditional detection methods ignore the complex interrelationships between Apps, and the purity of the detection is insufficient, hence cannot accurately and efficiently detect their complex behaviors, even difficult to detect. To combat the evolving Android malware attacks, we proposed method HeterSupervise which can analyze Android malware from an essential perspective. Firstly, We extracting various static and dynamic features from Apps using HSandroguard. To model different types of entities (i.e., code regions, sensitive API, package, signature) and rich relations among them, we present a heterogeneous graph for modeling. Secondly, in order to get the feature representation of each node, we design the HGN-embedding method to obtain the embedding of nodes belong to different types. Thirdly, we build HG-CNN classifiers based on various typical CNNs to detect unknown Android Apps. We integrate the above methods as a system Heter-Supervisor. Comprehensive experiments show that HeterSupervisor achieves more than 97% accuracy, and outperforms the state-of-the-art methods in efficiency with 60% improvement.
History
Pagination
328-335
Location
Yanuca Island, Cuvu, Fiji
Start date
2020-12-14
End date
2020-12-16
ISBN-13
9781728176499
Language
eng
Publication classification
E1 Full written paper - refereed
Editor/Contributor(s)
[Unknown]
Title of proceedings
Proceedings of the 2020 IEEE 22nd International Conference on High Performance Computing and Communications, IEEE 18th International Conference on Smart City and IEEE 6th International Conference on Data Science and Systems, HPCC-SmartCity-DSS
Event
IEEE 22nd International Conference on High Performance Computing and Communications; IEEE 18th International Conference on Smart City; IEEE 6th International Conference on Data Science and Systems (HPCC/SmartCity/DSS) (2020 : Yanuca Island, Cuvu, Fiji)