An Android Malware Detection and Malicious Code Location Method Based on Graph Neural Network
Qing Bo Wu, Peng Sun, Xueshu Hong, Xueling Zhu, Bo Liu · 2021
In recent years, enormously Android malware poses a significant threat to Android platform security. To detect malicious applications, researchers have done a lot of work, in which finding and locating malicious code segments is an important research content. In the previous research, most detection methods cannot directly locate malicious code, and some methods with the locate ability can only find some specific types of malicious operations. This paper proposed a graph convolution algorithm and weighted mechanism to find malicious nodes implied in the Android application function call graph and provided a general method for malicious code location. We analyzed the sub-graph structural differences between benign code and malicious payload in the function call graph, constructed graph convolution operation to make the nodes in the graph learn the surrounding sub-graph structure, designed the weighting mechanism to set the malicious score to every code node, and filtered out the nodes with the highest malicious score to locate the malicious code fragments. On the dataset composed of 2650 malicious and 2650 benign applications, the accuracy of malware detection is 92.6%, and the accuracy of malicious code location is between 72.6% and 88.1%, indicating that our method is accurate and efficient.