Android Malware Detection Model Incorporating Function Call Graph and Permission
Zekun Xia, Shaofei Wu · 2024
The proliferation of malicious software in the smartphone market, particularly targeting the Android operating system, has sparked a need for accurate detection methodologies. Leveraging machine learning and deep learning techniques, prior research has focused on feature extraction from APK files to identify such threats. However, the reliance solely on single-dimensional feature vectors, such as permissions extracted from manifest files (AndroidManifest.xml), often falls short in accurately predicting malware because code obfuscation makes accurate prediction difficult.”. In response, this paper presents a hybrid detection approach. Initially, permission data sourced from the APK manifest file is fed into a multilayer perceptron (MLP) model, yielding prediction result A with an accuracy of 91.81%. Subsequently, function call graphs (FCGs) extracted from APKs are processed by a graph convolutional network (GCN) model, producing prediction result B with an accuracy of 93.50%. These two prediction sets are then amalgamated, considering both model accuracies and individual APK prediction probabilities. Introducing a novel feature ui, computed as the product of ai(model accuracy) and pi(APK prediction probability), facilitates the integration process. Utilizing these enhanced features, a logistic regression meta-model is trained, achieving a prediction accuracy of 96.50%.