Ensemble-learning-based android malware detection using hybrid features
Z.X. Li W.H. Li, Yinghua Zhou · 2024
Against the backdrop of pervasive usage of Android operating system, the continuous emergence of Android malware with evolving evasion techniques poses a significant challenge, making it necessary to establish a robust security defense system for Android devices. To achieve this goal, a CNN-Ensemble model is proposed in this paper for detecting malicious Android software, leveraging the excellent feature extraction and dimensionality reduction capabilities of convolutional neural networks(CNNs) and the ability of ensemble learning models to achieve satisfactory classification results without extensive data training. Firstly, DEX files of Android software are converted into greyscale “vector” images using reverse engineering tool to serve as static features input for a CNN. Secondly, the Monkey tool is employed for dynamic execution of Android applications, and the strace tool is used to trace execution behavior of the program. The number of system calls made by software is adopted as dynamic data input for the proposed ensemble model. The proposed method concatenates feature vectors outputted by the CNN and the ensemble models and feed them into a gradient boosting classifier for final prediction. Experiments are carried out and the results show that the proposed CNN-Ensemble model achieves higher performance than those of the existing ensemble methods.