Deep Learning for Android Malware Detection and Classification Using Hybrid-Based Analysis: A Comparative Study

Arga Prayoga, Raden Budiarto Hadiprakoso, Ray Novita Yasa, Girinoto · 2023

The Android operating system is the fastestgrowing mobile operating system due to its open-source nature. However, the popularity of Android does not always have a positive impact on its users. One of the threats to Android users is the presence of malicious software (malware). Therefore, preventive measures need to be taken to detect and classify malware. One way to do this is through deep learning. This study compares single-view deep learning and multi-view deep learning architectures to detect and classify Android malware by utilizing system calls, network flows, and static features of an application. The deep learning models are built using three different algorithms, namely Bi-LSTM and Bi-GRU, to process system calls, and MLP, to process network flows and static features. In the single-view deep learning architecture, each feature is processed separately in the model. In contrast, in multi-view deep learning, all three features are processed in a single model combined with the concatenate function. After going through the model training and evaluation stages, the research results show that the best models for binary classification architecture are the Bi-GRU and Bi-LSTM models with results of up to 100%. Meanwhile, in the multi-class classification architecture, the MLP model based on static features obtained results of 94%.

Read the paper · More papers on PaperTik