A static analysis approach for Android permission-based malware detection systems.

Journal: PloS one
Published Date:

Abstract

The evolution of malware is causing mobile devices to crash with increasing frequency. Therefore, adequate security evaluations that detect Android malware are crucial. Two techniques can be used in this regard: Static analysis, which meticulously examines the full codes of applications, and dynamic analysis, which monitors malware behaviour. While both perform security evaluations successfully, there is still room for improvement. The goal of this research is to examine the effectiveness of static analysis to detect Android malware by using permission-based features. This study proposes machine learning with different sets of classifiers was used to evaluate Android malware detection. The feature selection method in this study was applied to determine which features were most capable of distinguishing malware. A total of 5,000 Drebin malware samples and 5,000 Androzoo benign samples were utilised. The performances of the different sets of classifiers were then compared. The results indicated that with a TPR value of 91.6%, the Random Forest algorithm achieved the highest level of accuracy in malware detection.

Authors

  • Juliza Mohamad Arif
    Faculty of Computing, Universiti Malaysia Pahang, Pekan, Pahang, Malaysia.
  • Mohd Faizal Ab Razak
    Faculty of Computing, Universiti Malaysia Pahang, Pekan, Pahang, Malaysia.
  • Suryanti Awang
    Faculty of Computer System and Software Engineering, University Malaysia Pahang UMP, Pahang, Malaysia.
  • Sharfah Ratibah Tuan Mat
    Faculty of Computing, Universiti Malaysia Pahang, Pekan, Pahang, Malaysia.
  • Nor Syahidatul Nadiah Ismail
    Faculty of Computing, Universiti Malaysia Pahang, Pekan, Pahang, Malaysia.
  • Ahmad Firdaus
    Faculty of Computer Systems and Software Engineering, Universiti Malaysia Pahang, 26300, Kuantan, Pahang, Malaysia.