Detecting Android Malware by Mining Enhanced System Call Graphs

Yunmar, Rajif Agung and Kusumawardani, Sri Suning and Widyawan, Widyawan and Mohsen, Fadi (2024) Detecting Android Malware by Mining Enhanced System Call Graphs. International Journal of Computer Network and Information Security, 16 (2). 28 – 41. ISSN 20749090

[thumbnail of IJCNIS-V16-N2-3.pdf] Text
IJCNIS-V16-N2-3.pdf
Restricted to Registered users only

Download (945kB) | Request a copy

Abstract

The persistent threat of malicious applications targeting Android devices has been growing in numbers and severity. Numerous techniques have been utilized to defend against this thread, including heuristic-based ones, which are able to detect unknown malware. Among the many features that this technique uses are system calls. Researchers have used several representation methods to capture system calls, such as histograms. However, some information may be lost if the system calls as a feature is only represented as a 1-dimensional vector. Graphs can represent the interaction of different system calls in an unusual or suspicious way, which can indicate malicious behavior. This study uses machine learning algorithms to recognize malicious behavior represented in a graph. The system call graph was fed into machine learning algorithms such as AdaBoost, Decision Table, Naïve Bayes, Random Forest, IBk, J48, and Logistic regression. We further employ a series feature selection method to improve detection accuracy and eliminate computational complexity. Our experiment results show that the proposed method has reduced feature dimension to 91.95 and provides 95.32 detection accuracy. © 2024, Modern Education and Computer Science Press. All rights reserved.

Item Type: Article
Additional Information: Cited by: 0; All Open Access, Bronze Open Access
Subjects: Q Science > Q Science (General)
T Technology > T Technology (General)
Divisions: Faculty of Engineering > Electrical and Information Technology Department
Depositing User: Sri JUNANDI
Date Deposited: 14 Jan 2025 07:38
Last Modified: 14 Jan 2025 07:38
URI: https://ir.lib.ugm.ac.id/id/eprint/12409

Actions (login required)

View Item
View Item