Employing combined spatial and frequency domain image features for machine learning-based malware detection

被引:1
作者
Bashar, Abul [1 ]
机构
[1] Prince Mohammad Bin Fahd Univ, Dept Comp Engn, Khobar 31952, Saudi Arabia
来源
ELECTRONIC RESEARCH ARCHIVE | 2024年 / 32卷 / 07期
关键词
image-based data; spatial and frequency domain; malware identification; machine learning classifiers; feature extraction; feature hybridization; FRAMEWORK;
D O I
10.3934/era.2024192
中图分类号
O1 [数学];
学科分类号
0701 ; 070101 ;
摘要
The ubiquitous adoption of Android devices has unfortunately brought a surge in malware threats, compromising user data, privacy concerns, and financial and device integrity, to name a few. To combat this, numerous efforts have explored automated botnet detection mechanisms, with anomalybased approaches leveraging machine learning (ML) gaining attraction due to their signature-agnostic nature. However, the problem lies in devising accurate ML models which capture the ever evolving landscape of malwares by effectively leveraging all the possible features from Android application packages (APKs).This paper delved into this domain by proposing, implementing, and evaluating an imagebased Android malware detection (AMD) framework that harnessed the power of feature hybridization. The core idea of this framework was the conversion of text-based data extracted from Android APKs into grayscale images. The novelty aspect of this work lied in the unique image feature extraction strategies and their subsequent hybridization to achieve accurate malware classification using ML models. More specifically, four distinct feature extraction methodologies, namely, Texture and histogram of oriented gradients (HOG) from spatial domain, and discrete wavelet transform (DWT) and Gabor from the frequency domain were employed to hybridize the features for improved malware identification. To this end, three image-based datasets, namely, Dex, Manifest, and Composite, derived from the information security centre of excellence (ISCX) Android Malware dataset, were leveraged to evaluate the optimal data source for botnet classification. Popular ML classifiers, including naive Bayes (NB), multilayer perceptron (MLP), support vector machine (SVM), and random forest (RF), were employed for the classification task. The experimental results demonstrated the efficacy of the proposed framework, achieving a peak classification accuracy of 93.03% and recall of 97.1% for the RF classifier using the Manifest dataset and a combination of Texture and HOG features. These findings validate the proof-of-concept and provide valuable insights for researchers exploring ML/deep learning (DL) approaches in the domain of AMD.
引用
收藏
页码:4255 / 4290
页数:36
相关论文
共 45 条
[1]  
Aggarwal N., 2012, J SIGNAL INFORM PROC, V3, P146, DOI [DOI 10.4236/JSIP.2012.32019, 10.4236/ jsip.2012.32019, 10.4236/jsip.2012.32019]
[2]   Empirical Comparisons for Combining Balancing and Feature Selection Strategies for Characterizing Football Players Using FIFA Video Game System [J].
Al-Asadi, Mustafa A. ;
Tasdemir, Sakir .
IEEE ACCESS, 2021, 9 :149266-149286
[3]   Deep Learning Methods for Malware and Intrusion Detection: A Systematic Literature Review [J].
Ali, Rahman ;
Ali, Asmat ;
Iqbal, Farkhund ;
Hussain, Mohammed ;
Ullah, Farhan .
SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
[4]   An Automated Vision-Based Deep Learning Model for Efficient Detection of Android Malware Attacks [J].
Almomani, Iman ;
Alkhayer, Aala ;
El-Shafai, Walid .
IEEE ACCESS, 2022, 10 :2700-2720
[5]  
[Anonymous], 2008, WORLD ACAD SCI ENG T
[6]  
AppBrain, 2024, Number of Android Applications on Google Play (Dec 2024) WWW Document
[7]   Embracing Mobile App Evolution via Continuous Ecosystem Mining and Characterization [J].
Cai, Haipeng .
2020 IEEE/ACM 7TH INTERNATIONAL CONFERENCE ON MOBILE SOFTWARE ENGINEERING AND SYSTEMS, MOBILESOFT, 2020, :31-35
[8]   A Longitudinal Study of Application Structure and Behaviors in Android [J].
Cai, Haipeng ;
Ryder, Barbara .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2021, 47 (12) :2934-2955
[9]   Assessing and Improving Malware Detection Sustainability through App Evolution Studies [J].
Cai, Haipeng .
ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2020, 29 (02)
[10]   DroidCat: Effective Android Malware Detection and Categorization via App-Level Profiling [J].
Cai, Haipeng ;
Meng, Na ;
Ryder, Barbara ;
Yao, Daphne .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (06) :1455-1470