NTPDroid: A Hybrid Android Malware Detector Using Network Traffic and System Permissions
Anshul Arora, Sateesh Kumar Peddoju · 2018
Two kinds of techniques, namely Static and Dynamic Analysis, have been proposed in the literature to detect Android malware. Permissions and Network Traffic are the widely used detection attributes. Malicious apps download malware at run-time and evade static permissions based detection while they can be detected by the network traffic. The malware that do not require network connectivity evade network traffic based detection which can be detected by permissions analysis. Therefore, we believe that combining the network traffic and system permissions will enhance the detection rate. Hence, in this work, we combine both the attributes and propose a hybrid detection model named NTPDroid, that extracts Network Traffic features and Permissions from the applications. To the best of our knowledge, this is the first attempt towards combining these important sources of Android malware detection. We train and test the proposed model using the FP-Growth algorithm to generate the frequent patterns consisting of traffic features and permissions. Experimental results demonstrate a detection accuracy of 94.25%, better than frequent patterns obtained independently.