TY - JOUR
T1 - Hawk
T2 - Rapid Android Malware Detection Through Heterogeneous Graph Attention Networks
AU - Hei, Yiming
AU - Yang, Renyu
AU - Peng, Hao
AU - Wang, Lihong
AU - Xu, Xiaolin
AU - Liu, Jianwei
AU - Liu, Hong
AU - Xu, Jie
AU - Sun, Lichao
N1 - Publisher Copyright:
© 2012 IEEE.
PY - 2024/4/1
Y1 - 2024/4/1
N2 - Android is undergoing unprecedented malicious threats daily, but the existing methods for malware detection often fail to cope with evolving camouflage in malware. To address this issue, we present Hawk, a new malware detection framework for evolutionary Android applications. We model Android entities and behavioral relationships as a heterogeneous information network (HIN), exploiting its rich semantic meta-structures for specifying implicit higher order relationships. An incremental learning model is created to handle the applications that manifest dynamically, without the need for reconstructing the whole HIN and the subsequent embedding model. The model can pinpoint rapidly the proximity between a new application and existing in-sample applications and aggregate their numerical embeddings under various semantics. Our experiments examine more than 80 860 malicious and 100 375 benign applications developed over a period of seven years, showing that Hawk achieves the highest detection accuracy against baselines and takes only 3.5 ms on average to detect an out-of-sample application, with the accelerated training time of $50\times $ faster than the existing approach.
AB - Android is undergoing unprecedented malicious threats daily, but the existing methods for malware detection often fail to cope with evolving camouflage in malware. To address this issue, we present Hawk, a new malware detection framework for evolutionary Android applications. We model Android entities and behavioral relationships as a heterogeneous information network (HIN), exploiting its rich semantic meta-structures for specifying implicit higher order relationships. An incremental learning model is created to handle the applications that manifest dynamically, without the need for reconstructing the whole HIN and the subsequent embedding model. The model can pinpoint rapidly the proximity between a new application and existing in-sample applications and aggregate their numerical embeddings under various semantics. Our experiments examine more than 80 860 malicious and 100 375 benign applications developed over a period of seven years, showing that Hawk achieves the highest detection accuracy against baselines and takes only 3.5 ms on average to detect an out-of-sample application, with the accelerated training time of $50\times $ faster than the existing approach.
KW - Android
KW - graph representation learning
KW - heterogeneous information network (HIN)
KW - malware detection
UR - https://www.scopus.com/pages/publications/85114630500
U2 - 10.1109/TNNLS.2021.3105617
DO - 10.1109/TNNLS.2021.3105617
M3 - 文章
C2 - 34449398
AN - SCOPUS:85114630500
SN - 2162-237X
VL - 35
SP - 4703
EP - 4717
JO - IEEE Transactions on Neural Networks and Learning Systems
JF - IEEE Transactions on Neural Networks and Learning Systems
IS - 4
ER -