详细信息

Detection of Android Malware Based on Deep Forest and Feature Enhancement  ( SCI-EXPANDED收录 EI收录)  

文献类型:期刊文献

英文题名:Detection of Android Malware Based on Deep Forest and Feature Enhancement

作者:Zhang, Xueqin[1,2];Wang, Jiyuan[1];Xu, Jinyu[3];Gu, Chunhua[1]

机构:[1]East China Univ Sci & Technol, Coll Informat Sci & Engn, Shanghai 200237, Peoples R China;[2]Shanghai Key Lab Comp Software Evaluating & Testin, Shanghai 201112, Peoples R China;[3]Hubei Univ Automot Technol, Sch Elect & Informat Engn, Shiyan 442002, Hubei, Peoples R China

年份:2023

卷号:11

起止页码:29344

外文期刊名:IEEE ACCESS

收录:;EI(收录号:20231413850981);WOS:【SCI-EXPANDED(收录号:WOS:000965450500001)】;

基金:This work was supported by the National Natural Science Foundation of China.

语种:英文

外文关键词:Android malware; anomaly detection; encrypted traffic; feature enhancement; deep forest

摘要:Detecting Android malware in its spread or download stage is a challenging work, which can realize early detection of malware before it reaches user side. In this paper, we propose a two-stage detection framework based on feature enhancement and cascade deep forest. This method can detect the traffic generated in the encrypted transmission process of Android malware. The first stage realizes the binary classification of benign and malicious software. The second stage realizes the multi-classification of different categories of malware. To enhance data representation, convolutional neural networks is used to extract benign and malicious features in the first stage, and the principal component analysis method is used to extract the malicious features in the second stage. Theses extracted features are spliced with the payload part of the traffic to form fusion features for classification task. In order to adapt to different scale of samples, especially for the small-scale sample, cascaded deep forest method is proposed to construct the classification model. In this model, many layers that consist of base classifiers are cascaded and the number of layers can be automatically adjusted according to the scale of the samples. With different combinations of base classifiers in each layer, the optima detection accuracy is archived in the two stages. The experimental results on several datasets prove that the proposed method is effective for encrypted transmission detection of Android malware. It is also suitable for the detection of unknown attacks.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心