Hybrid Classification Model to Detect Android Application-Collusion
Md Faiz Iqbal Faiz, Md. Anwar Hussain · 2020
Attacks launch by Android malware are getting harder to detect day by day. One such attack is Android application-collusion in short app-collusion. In this attack, more than one app participates. In brief, App-collusion is a scenario in which two or more applications collaborate to launch an attack on the smartphone. The applications in app-collusion need not be malicious. We propose a classification model that consists of two stages to detect app-collusion. The first stage is a hybrid classifier that consists of the KMeans clustering algorithm and a set of linear Support Vector Machines (SVMs). We input a dataset of benign and malicious applications to the first stage - the KMeans algorithm partitions the dataset into several clusters. We train a linear SVM on each cluster. We use the learned parameters of the linear SVMs to make a parameter vector. The second stage of our classification model uses the parameter vector and a lightweight discriminative function to detect app-collusion. Our classification model can detect both colluding app-pairs and single malicious applications. Our proposed model is less-compute intensive and straightforward to implement.