Android malware detection using network traffic based on sequential deep learning models

被引:14
|
作者
Fallah, Somayyeh [1 ]
Bidgoly, Amir Jalaly [1 ]
机构
[1] Univ Qom, Dept Informat Technol & Comp Engn, Qom, Iran
来源
SOFTWARE-PRACTICE & EXPERIENCE | 2022年 / 52卷 / 09期
关键词
LSTM; malware detection; network traffic analysis; sequential deep learning; smartphone;
D O I
10.1002/spe.3112
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The increasing trend of smartphone capabilities has caught the attention of many users. This has led to the emergence of malware that threatening the users' privacy and security. Many malware detection methods have been proposed to deal with emerging threats. One of the most effective ones is to use network traffic analysis. This article proposed a method based on LSTM (Long Short-term Memory) for malware detection which is capable of not only distinguishing malware and benign samples, but also detecting and identify the new and unseen families of malware. As far as we know, this is the first time that traffic data has been modeled as a sequence of flows and a sequential based deep learning model is employed. In this article, we have performed several case studies to exhibit the capabilities of the proposed method including malware detection, malware family identification, new (not seen before) malware family detection, as well as evaluating the minimum time required to detect malware. The case studies show that the model is even capable of detecting new families of malware with more than 90% accuracy, although these results can only be verified on existing families in this dataset and such a claim cannot be generalized to other examples of malware. Moreover, it is shown the model is able to detect the malware through capturing 50 connection flows (about 1600 packets in average) with the AUC of more than 99.9%.
引用
收藏
页码:1987 / 2004
页数:18
相关论文
共 50 条
  • [1] Using network traffic analysis deep learning based Android malware detection
    Utku A.
    Journal of the Faculty of Engineering and Architecture of Gazi University, 2022, 37 (04): : 1823 - 1838
  • [2] Deep and Broad Learning based Detection of Android Malware via Network Traffic
    Wang, Shanshan
    Chen, Zhenxiang
    Yan, Qiben
    Ji, Ke
    Wang, Lin
    Yang, Bo
    Conti, Mauro
    2018 IEEE/ACM 26TH INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE (IWQOS), 2018,
  • [3] A Comparison of Machine and Deep Learning Models for Detection and Classification of Android Malware Traffic
    Bovenzi, Giampaolo
    Cerasuolo, Francesco
    Montieri, Antonio
    Nascita, Alfredo
    Persico, Valerio
    Pescape, Antonio
    2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,
  • [4] A Two-Layer Deep Learning Method for Android Malware Detection Using Network Traffic
    Feng, Jiayin
    Shen, Limin
    Chen, Zhen
    Wang, Yuying
    Li, Hui
    IEEE ACCESS, 2020, 8 : 125786 - 125796
  • [5] Android Malware Detection Using Deep Learning
    Elayan, Omar N.
    Mustafa, Ahmad M.
    12TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT) / THE 4TH INTERNATIONAL CONFERENCE ON EMERGING DATA AND INDUSTRY 4.0 (EDI40) / AFFILIATED WORKSHOPS, 2021, 184 : 847 - 852
  • [6] Malware Detection Using Network Traffic Analysis in Android Based Mobile Devices
    Arora, Anshul
    Garg, Shree
    Peddoju, Sateesh K.
    2014 EIGHTH INTERNATIONAL CONFERENCE ON NEXT GENERATION MOBILE APPS, SERVICES AND TECHNOLOGIES (NGMAST), 2014, : 66 - 71
  • [7] Android Malware Detection Based on Network Traffic Using Decision Tree Algorithm
    Zulkifli, Aqil
    Hamid, Isredza Rahmi A.
    Shah, Wahidah Md
    Abdullah, Zubaile
    RECENT ADVANCES ON SOFT COMPUTING AND DATA MINING (SCDM 2018), 2018, 700 : 485 - 494
  • [8] Android Malware Detection Using Deep Learning Methods
    Lukas, Robert
    Kolaczek, Grzegorz
    2021 IEEE 30TH INTERNATIONAL CONFERENCE ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES (WETICE 2021), 2021, : 119 - 124
  • [9] Review of Android Malware Detection Based on Deep Learning
    Wang, Zhiqiang
    Liu, Qian
    Chi, Yaping
    IEEE ACCESS, 2020, 8 : 181102 - 181126
  • [10] Research of Android Malware Detection Based on Network Traffic Monitoring
    Li, Jun
    Zhai, Lidong
    Zhang, Xinyou
    Quan, Daiyong
    PROCEEDINGS OF THE 2014 9TH IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS (ICIEA), 2014, : 1739 - +