跳到主要导航 跳到搜索 跳到主要内容

Hawk: Rapid Android Malware Detection Through Heterogeneous Graph Attention Networks

  • Beihang University
  • University of Leeds
  • National Computer Network Emergency Response Technical Team
  • East China Normal University
  • Shanghai Trusted Industrial Control Platform Co., Ltd.
  • Lehigh University

科研成果: 期刊稿件文章同行评审

摘要

Android is undergoing unprecedented malicious threats daily, but the existing methods for malware detection often fail to cope with evolving camouflage in malware. To address this issue, we present Hawk, a new malware detection framework for evolutionary Android applications. We model Android entities and behavioral relationships as a heterogeneous information network (HIN), exploiting its rich semantic meta-structures for specifying implicit higher order relationships. An incremental learning model is created to handle the applications that manifest dynamically, without the need for reconstructing the whole HIN and the subsequent embedding model. The model can pinpoint rapidly the proximity between a new application and existing in-sample applications and aggregate their numerical embeddings under various semantics. Our experiments examine more than 80 860 malicious and 100 375 benign applications developed over a period of seven years, showing that Hawk achieves the highest detection accuracy against baselines and takes only 3.5 ms on average to detect an out-of-sample application, with the accelerated training time of $50\times $ faster than the existing approach.

源语言英语
页(从-至)4703-4717
页数15
期刊IEEE Transactions on Neural Networks and Learning Systems
35
4
DOI
出版状态已出版 - 1 4月 2024

指纹

探究 'Hawk: Rapid Android Malware Detection Through Heterogeneous Graph Attention Networks' 的科研主题。它们共同构成独一无二的指纹。

引用此