Detecting Novel Malware Classes with a Foundational Multi-Modality Data Analysis Model

3Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.

Abstract

With the increasing prevalence of Android software, protecting it against malicious threats has become a critical concern. Traditional malware detection methods, tailored for static environments, often fail to adapt to evolving threats in dynamic environments. To address the challenge of detecting evolving malware, we introduce DMDroid, a novel multi-modal fusion-based framework for malware analysis and detection. DMDroid leverages an array of feature extraction technologies and advanced deep learning models to analyze data, enhanced by a multi-head attention mechanism. This mechanism optimizes the integration of diverse static features from graph-based and image-based modalities, including permissions, API calls, opcodes, and bytecode sequences, prioritizing critical features to effectively detect new and evolving malware threats. We evaluate DMDroid in various realistic environments. Experiments show that compared to Bai, Drebin, and MaMa-pkg detector, DMDroid can improve the detection accuracy by 117.56%, 122.11%, and 119.47%, respectively. Compared to an unimodal approach, DMDroid can enhance the accuracy, macro-averaged F1 score, and weighted-averaged F1 score by 143.25%, 75.84% and 279.22%. The prototype can help to improve the quality and security of Android malware analysis and detection.

Cite

CITATION STYLE

APA

Dai, X., Yu, Z., Liang, C., Gao, C., He, Q., Wu, D., & Xu, Z. (2024). Detecting Novel Malware Classes with a Foundational Multi-Modality Data Analysis Model. Data Intelligence, 6(4), 968–993. https://doi.org/10.3724/2096-7004.di.2024.0056

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free