FLSH: A Framework Leveraging Similarity Hashing for Android Malware and Variant Detection

被引:0
|
作者
Hadi, Hassan Jalil [1 ,2 ]
Khalid, Alina [1 ]
Hussain, Faisal Bashir [1 ]
Ahmad, Naveed [2 ]
Alshara, Mohammed Ali [2 ]
机构
[1] Bahria Univ, Cyber Reconnaissance Combat Ctr, Dept Comp Sci, Islamabad 44220, Pakistan
[2] Prince Sultan Univ, Coll Comp & Informat Sci, Riyadh 11586, Saudi Arabia
来源
IEEE ACCESS | 2025年 / 13卷
关键词
Malware; Feature extraction; Accuracy; Classification algorithms; Operating systems; Trojan horses; Support vector machines; Static analysis; Process control; Android malware; fuzzy hashing; malware classification; similarity hashing; deep learning;
D O I
10.1109/ACCESS.2025.3537110
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As technology advances, the frequency and complexity of cyberattacks continue to rise, with Android OS, given its significant market share, becoming a prime target for sophisticated malware attacks. While the core categories of malware remain consistent, minor modifications often allow these variants to evade detection, posing significant challenges for security systems. To address this, various techniques and algorithms have been employed to improve malware detection and classification. In this paper, we focus on leveraging fuzzy hashes to calculate the similarity index between files, aiding in the identification of malicious content within seemingly legitimate APK files. Our research enhances the accuracy and reliability of fuzzy hashes, particularly for static features, in detecting Android malware and its variants. Unlike traditional approaches, our method employs a distinctive static feature-based fuzzy hashing technique. We conducted experiments on a dataset of 2000 APK files, including both benign and malicious samples, and classified malware into six categories trojan, adware, spyware, virus, downloader, and hacktool. The results showed a significant improvement in precision, recall, and F-measure, achieving an overall accuracy of 96.67%, without relying on complex machine learning or deep learning methods.
引用
收藏
页码:26142 / 26156
页数:15
相关论文
共 50 条
  • [21] Malware Detection: A Framework for Reverse Engineered Android Applications Through Machine Learning Algorithms
    Urooj, Beenish
    Shah, Munam Ali
    Maple, Carsten
    Abbasi, Muhammad Kamran
    Riasat, Sidra
    IEEE ACCESS, 2022, 10 : 89031 - 89050
  • [22] A brief survey of deep learning methods for android Malware detection
    Joomye, Abdurraheem
    Ling, Mee Hong
    Yau, Kok-Lim Alvin
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2025, 16 (02) : 711 - 733
  • [23] Android malware detection techniques: A literature review
    Dhalaria M.
    Gandotra E.
    Recent Patents on Engineering, 2021, 15 (02) : 225 - 245
  • [24] An Android Malware Detection Approach Based on SIMGRU
    Zhou, Hanxun
    Yang, Xinlin
    Pan, Hong
    Guo, Wei
    IEEE ACCESS, 2020, 8 : 148404 - 148410
  • [25] “Andromaly”: a behavioral malware detection framework for android devices
    Asaf Shabtai
    Uri Kanonov
    Yuval Elovici
    Chanan Glezer
    Yael Weiss
    Journal of Intelligent Information Systems, 2012, 38 : 161 - 190
  • [26] "Andromaly": a behavioral malware detection framework for android devices
    Shabtai, Asaf
    Kanonov, Uri
    Elovici, Yuval
    Glezer, Chanan
    Weiss, Yael
    JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2012, 38 (01) : 161 - 190
  • [27] MalDozer: Automatic framework for android malware detection using deep learning
    Karbab, ElMouatez Billah
    Debbabi, Mourad
    Derhab, Abdelouahid
    Mouheb, Djedjiga
    DIGITAL INVESTIGATION, 2018, 24 : S48 - S59
  • [28] GMADV: An android malware variant generation and classification adversarial training framework
    Li, Shuangcheng
    Tang, Zhangguo
    Li, Huanzhou
    Zhang, Jian
    Wang, Han
    Wang, Junfeng
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 84
  • [29] Meta-SonifiedDroid: Metaheuristics for Optimizing Sonified Android Malware Detection
    Tarwireyi, Paul
    Terzoli, Alfredo
    Adigun, Matthew O.
    IEEE ACCESS, 2024, 12 : 134779 - 134808
  • [30] A Survey on Android Malware Detection Techniques Using Supervised Machine Learning
    Altaha, Safa J.
    Aljughaiman, Ahmed
    Gul, Sonia
    IEEE ACCESS, 2024, 12 : 173168 - 173191