Abstract
While recent works have shown that deep learning method can improve the malware classification accuracy, the lack of the transparency has restricted its application in anti-virus scan engines. Existing researches have attempted to provide solutions to give high-fidelity explanations of the model’s decision. However, current methods are not optimized for application security task, leading to a poor performance in Android malware detection. In this paper, we propose a backtracking method to infer suspicious features of the apps to explain the reason of classification. Besides, we also propose a malware detection model based on the fusion convolutional neural network using different types of features (e.g., permission, API, URL, etc.). For maximizing the benefits of encompassing multiple feature types, our framework trains the sub-models for each type of features separately and merges them at the end of the system to obtain a comprehensive classification result. The experimental results show that the backtracking method has a significant improvement in fidelity level compared with existing methods. Furthermore, we evaluate the performance of the proposed framework with other existing works. Leveraging the backtracking method, our framework has better performance in classification and significantly reduces detection time by 69% compared with prior approaches.
Author supplied keywords
Cite
CITATION STYLE
Zhu, D., Xi, T., Jing, P., Wu, D., Xia, Q., & Zhang, Y. (2019). A transparent and multimodal malware detection method for android apps. In MSWiM 2019 - Proceedings of the 22nd International ACM Conference on Modeling, Analysis and Simulation of Wireless and Mobile Systems (pp. 51–60). Association for Computing Machinery, Inc. https://doi.org/10.1145/3345768.3355915
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.