Multi-view deep learning for zero-day Android malware detection

Publication typeJournal Article
Publication date2021-05-01
scimago Q1
wos Q2
SJR0.932
CiteScore10.0
Impact factor3.7
ISSN22142134, 22142126
Computer Networks and Communications
Software
Safety, Risk, Reliability and Quality
Abstract
Zero-day malware samples pose a considerable danger to users as implicitly there are no documented defences for previously unseen, newly encountered behaviour. Malware detection therefore relies on past knowledge to attempt to deal with zero-days. Often such insight is provided by a human expert hand-crafting and pre-categorising certain features as malicious. However, tightly coupled feature-engineering based on previous domain knowledge risks not being effective when faced with a new threat. In this work we decouple this human expertise, instead encapsulating knowledge inside a deep learning neural net with no prior understanding of malicious characteristics. Raw input features consist of low-level opcodes, app permissions and proprietary Android API package usage. Our method makes three main contributions. Firstly, a novel multi-view deep learning Android malware detector with no specialist malware domain insight used to select, rank or hand-craft input features. Secondly, a comprehensive zero-day scenario evaluation using the Drebin and AMD benchmarks, with our model achieving weighted average detection rates of 91% and 81% respectively, an improvement of up to 57% over the state-of-the-art. Thirdly, a 77% reduction in false positives on average compared to the state-of-the-art, with excellent F1 scores of 0.9928 and 0.9963 for the general detection task again on the Drebin and AMD benchmark datasets respectively.
Found 
Found 

Top-30

Journals

1
2
3
IEEE Access
3 publications, 5.26%
PeerJ Computer Science
2 publications, 3.51%
Applied Sciences (Switzerland)
2 publications, 3.51%
Expert Systems with Applications
2 publications, 3.51%
SN Computer Science
2 publications, 3.51%
Security and Communication Networks
2 publications, 3.51%
Computers and Security
2 publications, 3.51%
Processes
1 publication, 1.75%
Electronics (Switzerland)
1 publication, 1.75%
Sensors
1 publication, 1.75%
Journal of Cybersecurity and Privacy
1 publication, 1.75%
Computers, Materials and Continua
1 publication, 1.75%
Intelligent Automation and Soft Computing
1 publication, 1.75%
Machine Learning with Applications
1 publication, 1.75%
Procedia Computer Science
1 publication, 1.75%
Wiley Interdisciplinary Reviews Forensic Science
1 publication, 1.75%
Concurrency Computation Practice and Experience
1 publication, 1.75%
Communications in Computer and Information Science
1 publication, 1.75%
Journal of Intelligent and Fuzzy Systems
1 publication, 1.75%
ACM Computing Surveys
1 publication, 1.75%
Intelligent Decision Technologies
1 publication, 1.75%
Computers and Electrical Engineering
1 publication, 1.75%
International Journal of Critical Infrastructure Protection
1 publication, 1.75%
Symmetry
1 publication, 1.75%
Scientific Reports
1 publication, 1.75%
International Journal of Systems Assurance Engineering and Management
1 publication, 1.75%
IFIP Advances in Information and Communication Technology
1 publication, 1.75%
International Journal of Information Security
1 publication, 1.75%
Journal of Cyber Security Technology
1 publication, 1.75%
1
2
3

Publishers

5
10
15
20
Institute of Electrical and Electronics Engineers (IEEE)
20 publications, 35.09%
Elsevier
8 publications, 14.04%
Springer Nature
8 publications, 14.04%
MDPI
7 publications, 12.28%
PeerJ
2 publications, 3.51%
Taylor & Francis
2 publications, 3.51%
Wiley
2 publications, 3.51%
Hindawi Limited
2 publications, 3.51%
SAGE
2 publications, 3.51%
Association for Computing Machinery (ACM)
2 publications, 3.51%
Tech Science Press
1 publication, 1.75%
5
10
15
20
  • We do not take into account publications without a DOI.
  • Statistics recalculated weekly.

Are you a researcher?

Create a profile to get free access to personal recommendations for colleagues and new articles.
Metrics
57
Share
Cite this
GOST |
Cite this
GOST Copy
Millar S. et al. Multi-view deep learning for zero-day Android malware detection // Journal of Information Security and Applications. 2021. Vol. 58. p. 102718.
GOST all authors (up to 50) Copy
Millar S., Mclaughlin N., Martínez del Rincón J., Miller P. B. Multi-view deep learning for zero-day Android malware detection // Journal of Information Security and Applications. 2021. Vol. 58. p. 102718.
RIS |
Cite this
RIS Copy
TY - JOUR
DO - 10.1016/j.jisa.2020.102718
UR - https://doi.org/10.1016/j.jisa.2020.102718
TI - Multi-view deep learning for zero-day Android malware detection
T2 - Journal of Information Security and Applications
AU - Millar, Stuart
AU - Mclaughlin, Niall
AU - Martínez del Rincón, Jesús
AU - Miller, Paul B
PY - 2021
DA - 2021/05/01
PB - Elsevier
SP - 102718
VL - 58
SN - 2214-2134
SN - 2214-2126
ER -
BibTex
Cite this
BibTex (up to 50 authors) Copy
@article{2021_Millar,
author = {Stuart Millar and Niall Mclaughlin and Jesús Martínez del Rincón and Paul B Miller},
title = {Multi-view deep learning for zero-day Android malware detection},
journal = {Journal of Information Security and Applications},
year = {2021},
volume = {58},
publisher = {Elsevier},
month = {may},
url = {https://doi.org/10.1016/j.jisa.2020.102718},
pages = {102718},
doi = {10.1016/j.jisa.2020.102718}
}