Machine Learning in Anomaly Detection: Example of Colluded Applications Attack in Android Devices
Igor Khokhlov, Michael Perez, Leon Reznik · 2019
The paper investigates the feasibility of using machine learning (ML) applications for an anomaly-based unknown attack detection by monitoring system parameters on resource-constrained Android mobile devices. It introduces colluded applications example as a use case of unknown sophisticated attacks, examines its formalization models and possible scenarios as well as develops the machine learning classifiers for its detection. We investigate multiple attack cases and record them to produce datasets characterizing a memory consumption and a CPU cores clock speed changes during the attacks that could be employed to design classifiers based on ML techniques. For the attack detection, a few ML classifiers are presented and examined. The classifiers employ various ML techniques and models, such as feed-forward neural network and long short-term memory. Model performance in detecting multiple attack scenarios are presented. Classification models compared against various criteria.