FLSH: A Framework Leveraging Similarity Hashing for Android Malware and Variant Detection

被引:0
|
作者
Hadi, Hassan Jalil [1 ,2 ]
Khalid, Alina [1 ]
Hussain, Faisal Bashir [1 ]
Ahmad, Naveed [2 ]
Alshara, Mohammed Ali [2 ]
机构
[1] Bahria Univ, Cyber Reconnaissance Combat Ctr, Dept Comp Sci, Islamabad 44220, Pakistan
[2] Prince Sultan Univ, Coll Comp & Informat Sci, Riyadh 11586, Saudi Arabia
来源
IEEE ACCESS | 2025年 / 13卷
关键词
Malware; Feature extraction; Accuracy; Classification algorithms; Operating systems; Trojan horses; Support vector machines; Static analysis; Process control; Android malware; fuzzy hashing; malware classification; similarity hashing; deep learning;
D O I
10.1109/ACCESS.2025.3537110
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As technology advances, the frequency and complexity of cyberattacks continue to rise, with Android OS, given its significant market share, becoming a prime target for sophisticated malware attacks. While the core categories of malware remain consistent, minor modifications often allow these variants to evade detection, posing significant challenges for security systems. To address this, various techniques and algorithms have been employed to improve malware detection and classification. In this paper, we focus on leveraging fuzzy hashes to calculate the similarity index between files, aiding in the identification of malicious content within seemingly legitimate APK files. Our research enhances the accuracy and reliability of fuzzy hashes, particularly for static features, in detecting Android malware and its variants. Unlike traditional approaches, our method employs a distinctive static feature-based fuzzy hashing technique. We conducted experiments on a dataset of 2000 APK files, including both benign and malicious samples, and classified malware into six categories trojan, adware, spyware, virus, downloader, and hacktool. The results showed a significant improvement in precision, recall, and F-measure, achieving an overall accuracy of 96.67%, without relying on complex machine learning or deep learning methods.
引用
收藏
页码:26142 / 26156
页数:15
相关论文
共 50 条
  • [31] Detecting Malware with Similarity to Android applications
    Park, Wonjoo
    Kim, Sun-joong
    Ryu, Won
    2015 INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC), 2015, : 1249 - 1251
  • [32] A multi-model ensemble learning framework for imbalanced android malware detection
    Zhu, Hui-juan
    Li, Yang
    Wang, Liang-min
    Sheng, Victor S.
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 234
  • [33] Deep Belief Networks-based framework for malware detection in Android systems
    Saif, Dina
    El-Gokhy, S. M.
    Sallam, E.
    ALEXANDRIA ENGINEERING JOURNAL, 2018, 57 (04) : 4049 - 4057
  • [34] Malware Detection and Classification in Android Application Using Simhash-Based Feature Extraction and Machine Learning
    Al-Kahla, Wafaa
    Taqieddin, Eyad
    Shatnawi, Ahmed S.
    Al-Ouran, Rami
    IEEE ACCESS, 2024, 12 : 174255 - 174273
  • [35] Towards the Detection of Android Malware using Ensemble Features
    Aswini, A. M.
    Vinod, P.
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2015, 10 (01): : 14 - 26
  • [36] AndrEnsemble: Leveraging API Ensembles to Characterize Android Malware Families
    Mirzaei, Omid
    Suarez-Tangil, Guillermo
    de Fuentes, Jose M.
    Tapiador, Juan
    Stringhini, Gianluca
    PROCEEDINGS OF THE 2019 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS '19), 2019, : 307 - 314
  • [37] Framework for malware analysis in Android
    Urcuqui Lopez, Christian Camilo
    Navarro Cadavid, Andres
    SISTEMAS & TELEMATICA, 2016, 14 (37): : 45 - 56
  • [38] SEDMDroid: An Enhanced Stacking Ensemble Framework for Android Malware Detection
    Zhu, Huijuan
    Li, Yang
    Li, Ruidong
    Li, Jianqiang
    You, Zhuhong
    Song, Houbing
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2021, 8 (02): : 984 - 994
  • [39] Android malware detection: state of the art
    Muttoo S.K.
    Badhani S.
    International Journal of Information Technology, 2017, 9 (1) : 111 - 117
  • [40] A Hybrid Detection Method for Android Malware
    Fang, Qi
    Yang, Xiaohui
    Ji, Ce
    PROCEEDINGS OF 2019 IEEE 3RD INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2019), 2019, : 2127 - 2132