The Experts below are selected from a list of 1980 Experts worldwide ranked by ideXlab platform

Zhiyong Feng - One of the best experts on this subject based on the ideXlab platform.

  • Comparative analysis of feature representations and machine learning methods in Android Family classification
    Computer Networks, 2021
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    Abstract In order to overcome the lasting increase of Android Malware, Malware Family classification, which clusters Malware with the same features into one Family, has been proposed as an efficient way for Malware analysis. Several machine learning based approaches have been proposed for such task of Malware Family classification. However, due to the adoption of very different features and learning methods in different approaches, it is still an open question to explore: which approach works better for Malware Family classification? In this paper, we conduct extensive experiments to answer this question. For three widely known Android Malware datasets, we design five multi-classification methods for predicting Android Malware Family. Based on the survey of Android Malware analysis literatures and the observation of a large number of Android Malware, we construct a set of 250 common features shared by Android Malware. And we also collect 16873 documentary features from Android Developer as a comparison. Furthermore, we investigate the effects of transfer learning for adapting the model on three Malware datasets on different scales. Our empirical results show that (i) the classification methods perform very closely, with neural network model having marginally better performance (1% to 3% in F1-score), (ii) features contribute most for classification, especially to enhance API features on larger datasets, and (iii) it is model transferable across different Malware datasets based on various transfer learning tasks.

  • unsuccessful story about few shot Malware Family classification and siamese network to the rescue
    International Conference on Software Engineering, 2020
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    To battle the ever-increasing Android Malware, Malware Family classification, which classifies Malware with common features into a Malware Family, has been proposed as an effective Malware analysis method. Several machine-learning based approaches have been proposed for the task of Malware Family classification. Our study shows that Malware families suffer from several data imbalance, with many families with only a small number of Malware applications (referred to as few shot Malware families in this work). Unfortunately, this issue has been overlooked in existing approaches. Although existing approaches achieve high classification performance at the overall level and for large Malware families, our experiments show that they suffer from poor performance and generalizability for few shot Malware families, and traditionally downsampling method cannot solve the problem. To address the challenge in few shot Malware Family classification, we propose a novel siamese-network based learning method, which allows us to train an effective MultiLayer Perceptron (MLP) network for embedding Malware applications into a real-valued, continuous vector space by contrasting the Malware applications from the same or different families. In the embedding space, the performance of Malware Family classification can be significantly improved for all scales of Malware families, especially for few shot Malware families, which also leads to the significant performance improvement at the overall level.

  • ICSE - Unsuccessful Story about Few Shot Malware Family Classification and Siamese Network to the Rescue
    Proceedings of the ACM IEEE 42nd International Conference on Software Engineering, 2020
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    To battle the ever-increasing Android Malware, Malware Family classification, which classifies Malware with common features into a Malware Family, has been proposed as an effective Malware analysis method. Several machine-learning based approaches have been proposed for the task of Malware Family classification. Our study shows that Malware families suffer from several data imbalance, with many families with only a small number of Malware applications (referred to as few shot Malware families in this work). Unfortunately, this issue has been overlooked in existing approaches. Although existing approaches achieve high classification performance at the overall level and for large Malware families, our experiments show that they suffer from poor performance and generalizability for few shot Malware families, and traditionally downsampling method cannot solve the problem. To address the challenge in few shot Malware Family classification, we propose a novel siamese-network based learning method, which allows us to train an effective MultiLayer Perceptron (MLP) network for embedding Malware applications into a real-valued, continuous vector space by contrasting the Malware applications from the same or different families. In the embedding space, the performance of Malware Family classification can be significantly improved for all scales of Malware families, especially for few shot Malware families, which also leads to the significant performance improvement at the overall level.

Yude Bai - One of the best experts on this subject based on the ideXlab platform.

  • Comparative analysis of feature representations and machine learning methods in Android Family classification
    Computer Networks, 2021
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    Abstract In order to overcome the lasting increase of Android Malware, Malware Family classification, which clusters Malware with the same features into one Family, has been proposed as an efficient way for Malware analysis. Several machine learning based approaches have been proposed for such task of Malware Family classification. However, due to the adoption of very different features and learning methods in different approaches, it is still an open question to explore: which approach works better for Malware Family classification? In this paper, we conduct extensive experiments to answer this question. For three widely known Android Malware datasets, we design five multi-classification methods for predicting Android Malware Family. Based on the survey of Android Malware analysis literatures and the observation of a large number of Android Malware, we construct a set of 250 common features shared by Android Malware. And we also collect 16873 documentary features from Android Developer as a comparison. Furthermore, we investigate the effects of transfer learning for adapting the model on three Malware datasets on different scales. Our empirical results show that (i) the classification methods perform very closely, with neural network model having marginally better performance (1% to 3% in F1-score), (ii) features contribute most for classification, especially to enhance API features on larger datasets, and (iii) it is model transferable across different Malware datasets based on various transfer learning tasks.

  • unsuccessful story about few shot Malware Family classification and siamese network to the rescue
    International Conference on Software Engineering, 2020
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    To battle the ever-increasing Android Malware, Malware Family classification, which classifies Malware with common features into a Malware Family, has been proposed as an effective Malware analysis method. Several machine-learning based approaches have been proposed for the task of Malware Family classification. Our study shows that Malware families suffer from several data imbalance, with many families with only a small number of Malware applications (referred to as few shot Malware families in this work). Unfortunately, this issue has been overlooked in existing approaches. Although existing approaches achieve high classification performance at the overall level and for large Malware families, our experiments show that they suffer from poor performance and generalizability for few shot Malware families, and traditionally downsampling method cannot solve the problem. To address the challenge in few shot Malware Family classification, we propose a novel siamese-network based learning method, which allows us to train an effective MultiLayer Perceptron (MLP) network for embedding Malware applications into a real-valued, continuous vector space by contrasting the Malware applications from the same or different families. In the embedding space, the performance of Malware Family classification can be significantly improved for all scales of Malware families, especially for few shot Malware families, which also leads to the significant performance improvement at the overall level.

  • ICSE - Unsuccessful Story about Few Shot Malware Family Classification and Siamese Network to the Rescue
    Proceedings of the ACM IEEE 42nd International Conference on Software Engineering, 2020
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    To battle the ever-increasing Android Malware, Malware Family classification, which classifies Malware with common features into a Malware Family, has been proposed as an effective Malware analysis method. Several machine-learning based approaches have been proposed for the task of Malware Family classification. Our study shows that Malware families suffer from several data imbalance, with many families with only a small number of Malware applications (referred to as few shot Malware families in this work). Unfortunately, this issue has been overlooked in existing approaches. Although existing approaches achieve high classification performance at the overall level and for large Malware families, our experiments show that they suffer from poor performance and generalizability for few shot Malware families, and traditionally downsampling method cannot solve the problem. To address the challenge in few shot Malware Family classification, we propose a novel siamese-network based learning method, which allows us to train an effective MultiLayer Perceptron (MLP) network for embedding Malware applications into a real-valued, continuous vector space by contrasting the Malware applications from the same or different families. In the embedding space, the performance of Malware Family classification can be significantly improved for all scales of Malware families, especially for few shot Malware families, which also leads to the significant performance improvement at the overall level.

Weiqing Huang - One of the best experts on this subject based on the ideXlab platform.

  • android Malware Family classification based on sensitive opcode sequence
    International Symposium on Computers and Communications, 2019
    Co-Authors: Jianguo Jiang, Chao Liu, Kai Chen, Hui Liu, Weiqing Huang
    Abstract:

    Android Malware Family classification is an advanced task in Android Malware analysis, detection and forensics. Existing methods and models have achieved a certain success for Android Malware detection, but the accuracy and the efficiency are still not up to the expectation, especially in the context of multiple class classification with imbalanced training data. To address those challenges, we propose an Android Malware Family classification model by analyzing the code’s specific semantic information based on sensitive opcode sequence. In this work, we construct a sensitive semantic feature-sensitive opcode sequence using opcodes, sensitive APIs, STRs and actions, and propose to analyze the code’s specific semantic information, generate a semantic related vector for Android Malware Family classification based on this feature. Besides, aiming at the families with minority, we adopt an oversampling technique based on the sensitive opcode sequence. Finally, we evaluate our method on Drebin dataset, and select the top 40 Malware families for experiments. The experimental results show that the Total Accuracy and Average AUC (Area Under Curve, AUC) reach 99.50% and 98.86% with 45. 17s per Android Malware, and even if the number of Malware families increases, these results remain good.

  • ISCC - Android Malware Family Classification Based on Sensitive Opcode Sequence
    2019 IEEE Symposium on Computers and Communications (ISCC), 2019
    Co-Authors: Jianguo Jiang, Chao Liu, Kai Chen, Hui Liu, Weiqing Huang
    Abstract:

    Android Malware Family classification is an advanced task in Android Malware analysis, detection and forensics. Existing methods and models have achieved a certain success for Android Malware detection, but the accuracy and the efficiency are still not up to the expectation, especially in the context of multiple class classification with imbalanced training data. To address those challenges, we propose an Android Malware Family classification model by analyzing the code’s specific semantic information based on sensitive opcode sequence. In this work, we construct a sensitive semantic feature-sensitive opcode sequence using opcodes, sensitive APIs, STRs and actions, and propose to analyze the code’s specific semantic information, generate a semantic related vector for Android Malware Family classification based on this feature. Besides, aiming at the families with minority, we adopt an oversampling technique based on the sensitive opcode sequence. Finally, we evaluate our method on Drebin dataset, and select the top 40 Malware families for experiments. The experimental results show that the Total Accuracy and Average AUC (Area Under Curve, AUC) reach 99.50% and 98.86% with 45. 17s per Android Malware, and even if the number of Malware families increases, these results remain good.

Zhenchang Xing - One of the best experts on this subject based on the ideXlab platform.

  • Comparative analysis of feature representations and machine learning methods in Android Family classification
    Computer Networks, 2021
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    Abstract In order to overcome the lasting increase of Android Malware, Malware Family classification, which clusters Malware with the same features into one Family, has been proposed as an efficient way for Malware analysis. Several machine learning based approaches have been proposed for such task of Malware Family classification. However, due to the adoption of very different features and learning methods in different approaches, it is still an open question to explore: which approach works better for Malware Family classification? In this paper, we conduct extensive experiments to answer this question. For three widely known Android Malware datasets, we design five multi-classification methods for predicting Android Malware Family. Based on the survey of Android Malware analysis literatures and the observation of a large number of Android Malware, we construct a set of 250 common features shared by Android Malware. And we also collect 16873 documentary features from Android Developer as a comparison. Furthermore, we investigate the effects of transfer learning for adapting the model on three Malware datasets on different scales. Our empirical results show that (i) the classification methods perform very closely, with neural network model having marginally better performance (1% to 3% in F1-score), (ii) features contribute most for classification, especially to enhance API features on larger datasets, and (iii) it is model transferable across different Malware datasets based on various transfer learning tasks.

  • unsuccessful story about few shot Malware Family classification and siamese network to the rescue
    International Conference on Software Engineering, 2020
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    To battle the ever-increasing Android Malware, Malware Family classification, which classifies Malware with common features into a Malware Family, has been proposed as an effective Malware analysis method. Several machine-learning based approaches have been proposed for the task of Malware Family classification. Our study shows that Malware families suffer from several data imbalance, with many families with only a small number of Malware applications (referred to as few shot Malware families in this work). Unfortunately, this issue has been overlooked in existing approaches. Although existing approaches achieve high classification performance at the overall level and for large Malware families, our experiments show that they suffer from poor performance and generalizability for few shot Malware families, and traditionally downsampling method cannot solve the problem. To address the challenge in few shot Malware Family classification, we propose a novel siamese-network based learning method, which allows us to train an effective MultiLayer Perceptron (MLP) network for embedding Malware applications into a real-valued, continuous vector space by contrasting the Malware applications from the same or different families. In the embedding space, the performance of Malware Family classification can be significantly improved for all scales of Malware families, especially for few shot Malware families, which also leads to the significant performance improvement at the overall level.

  • ICSE - Unsuccessful Story about Few Shot Malware Family Classification and Siamese Network to the Rescue
    Proceedings of the ACM IEEE 42nd International Conference on Software Engineering, 2020
    Co-Authors: Yude Bai, Zhenchang Xing, Zhiyong Feng
    Abstract:

    To battle the ever-increasing Android Malware, Malware Family classification, which classifies Malware with common features into a Malware Family, has been proposed as an effective Malware analysis method. Several machine-learning based approaches have been proposed for the task of Malware Family classification. Our study shows that Malware families suffer from several data imbalance, with many families with only a small number of Malware applications (referred to as few shot Malware families in this work). Unfortunately, this issue has been overlooked in existing approaches. Although existing approaches achieve high classification performance at the overall level and for large Malware families, our experiments show that they suffer from poor performance and generalizability for few shot Malware families, and traditionally downsampling method cannot solve the problem. To address the challenge in few shot Malware Family classification, we propose a novel siamese-network based learning method, which allows us to train an effective MultiLayer Perceptron (MLP) network for embedding Malware applications into a real-valued, continuous vector space by contrasting the Malware applications from the same or different families. In the embedding space, the performance of Malware Family classification can be significantly improved for all scales of Malware families, especially for few shot Malware families, which also leads to the significant performance improvement at the overall level.

Meng Chang Chen - One of the best experts on this subject based on the ideXlab platform.

  • Integration of Static and Dynamic Analysis for Malware Family Classification with Composite Neural Network
    arXiv: Cryptography and Security, 2019
    Co-Authors: Yao Saint Yen, Zhe Wei Chen, Ying Ren Guo, Meng Chang Chen
    Abstract:

    Deep learning has been used in the research of Malware analysis. Most classification methods use either static analysis features or dynamic analysis features for Malware Family classification, and rarely combine them as classification features and also no extra effort is spent integrating the two types of features. In this paper, we combine static and dynamic analysis features with deep neural networks for Windows Malware classification. We develop several methods to generate static and dynamic analysis features to classify Malware in different ways. Given these features, we conduct experiments with composite neural network, showing that the proposed approach performs best with an accuracy of 83.17% on a total of 80 Malware families with 4519 Malware samples. Additionally, we show that using integrated features for Malware Family classification outperforms using static features or dynamic features alone. We show how static and dynamic features complement each other for Malware classification.

  • antsdroid using rasmma algorithm to generate Malware behavior characteristics of android Malware Family
    Pacific Rim International Symposium on Dependable Computing, 2018
    Co-Authors: Shunchieh Chang, Yeali S Sun, Meng Chang Chen, Wulong Chuang, Bo Sun, Takeshi Takahashi
    Abstract:

    Malware developers often use various obfuscation techniques to generate polymorphic and metamorphic versions of malicious programs. As a result, variants of a Malware Family generally exhibit resembling behavior, and most importantly, they possess certain common essential codes so to achieve the same designed purpose. Meantime, keeping up with new variants and generating signatures for each individual in a timely fashion has been costly and inefficient for anti-virus software companies. It motivates us the idea of no more dancing with variants. In this paper, we aim to find a Malware Family's main characteristic operations or activities directly related to its intent. We propose a novel automatic dynamic Android profiling system and Malware Family runtime behavior signature generation method called Runtime API sequence Motif Mining Algorithm (RasMMA) based on the analysis of the sensitive and permission-related execution traces of the threads and processes of a set of variant APKs of a Malware Family. We show the effectiveness of using the generated Family signature to detect new variants using real-world dataset. Moreover, current anti-Malware tools usually treat detection models as a black box for classification and offer little explanations on how Malwares behave and how they proceed step by step to infiltrate targeted system and achieve the goal. We take Malware Family DroidKungFu as a case study to illustrate that the generated Family signature indeed captures key malicious activities of the Family.

  • antsdroid automatic Malware Family behaviour generation and analysis for android apps
    Australasian Conference on Information Security and Privacy, 2018
    Co-Authors: Yeali S Sun, Shun-wen Hsiao, Chienchun Chen, Meng Chang Chen
    Abstract:

    Malware developers often use various obfuscation techniques to generate polymorphic and metamorphic versions of Malwares. Keeping up with new variants and creating signatures for each individuals in a timely fashion has been an important problem but tedious works that anti-virus companies face all the time. It motivates us the idea of no more dancing with variants. In this paper, we aim to find a Malware Family’s main characteristic operations directly related to its intent. We propose global execution sequence alignment and segmentation algorithms to generate the execution stage chart of a Malware Family which presents a simple and easy-to-understand overview of the lifecycle as well as common and different operations that individual variants perform at a stage. We also present an automated dynamic Android Malware profiling and Family security analysis system in which we focus on the execution sequences of sensitive and permission-related API calls referred to as motifs of variants of Malware Family. To achieve the goal, we modify Android Debug Bridge (ADB) tool to add on several new features including enabling the recording of parameters and return value of an API call, the support of UID-based profiling to capture all the processes and threads to gain complete understanding of the activities of target Malware app, and per thread trace generation. Finally, we use real-world dataset to validate the proposed system and methods. The generated Family stage chart and motifs can provide security analysts semantics-rich understanding of what and how a Malware Family is designed and implemented. The main characteristic API call sequences of Malware families can be used as signatures for effective and efficient Malware detection in the future.

  • ACISP - ANTSdroid: Automatic Malware Family Behaviour Generation and Analysis for Android Apps
    Information Security and Privacy, 2018
    Co-Authors: Yeali S Sun, Shun-wen Hsiao, Chienchun Chen, Meng Chang Chen
    Abstract:

    Malware developers often use various obfuscation techniques to generate polymorphic and metamorphic versions of Malwares. Keeping up with new variants and creating signatures for each individuals in a timely fashion has been an important problem but tedious works that anti-virus companies face all the time. It motivates us the idea of no more dancing with variants. In this paper, we aim to find a Malware Family’s main characteristic operations directly related to its intent. We propose global execution sequence alignment and segmentation algorithms to generate the execution stage chart of a Malware Family which presents a simple and easy-to-understand overview of the lifecycle as well as common and different operations that individual variants perform at a stage. We also present an automated dynamic Android Malware profiling and Family security analysis system in which we focus on the execution sequences of sensitive and permission-related API calls referred to as motifs of variants of Malware Family. To achieve the goal, we modify Android Debug Bridge (ADB) tool to add on several new features including enabling the recording of parameters and return value of an API call, the support of UID-based profiling to capture all the processes and threads to gain complete understanding of the activities of target Malware app, and per thread trace generation. Finally, we use real-world dataset to validate the proposed system and methods. The generated Family stage chart and motifs can provide security analysts semantics-rich understanding of what and how a Malware Family is designed and implemented. The main characteristic API call sequences of Malware families can be used as signatures for effective and efficient Malware detection in the future.

  • PRDC - ANTSdroid: Using RasMMA Algorithm to Generate Malware Behavior Characteristics of Android Malware Family
    2018 IEEE 23rd Pacific Rim International Symposium on Dependable Computing (PRDC), 2018
    Co-Authors: Shunchieh Chang, Yeali S Sun, Meng Chang Chen, Wulong Chuang, Bo Sun, Takeshi Takahashi
    Abstract:

    Malware developers often use various obfuscation techniques to generate polymorphic and metamorphic versions of malicious programs. As a result, variants of a Malware Family generally exhibit resembling behavior, and most importantly, they possess certain common essential codes so to achieve the same designed purpose. Meantime, keeping up with new variants and generating signatures for each individual in a timely fashion has been costly and inefficient for anti-virus software companies. It motivates us the idea of no more dancing with variants. In this paper, we aim to find a Malware Family's main characteristic operations or activities directly related to its intent. We propose a novel automatic dynamic Android profiling system and Malware Family runtime behavior signature generation method called Runtime API sequence Motif Mining Algorithm (RasMMA) based on the analysis of the sensitive and permission-related execution traces of the threads and processes of a set of variant APKs of a Malware Family. We show the effectiveness of using the generated Family signature to detect new variants using real-world dataset. Moreover, current anti-Malware tools usually treat detection models as a black box for classification and offer little explanations on how Malwares behave and how they proceed step by step to infiltrate targeted system and achieve the goal. We take Malware Family DroidKungFu as a case study to illustrate that the generated Family signature indeed captures key malicious activities of the Family.