In recent years, Android malware has substantially increased both in incidence and developmental complexity. To address this, machine learning approaches are increasingly used to help Android systems detect such software. Such approaches are built on models and metrics encapsulating dynamic behaviors and/or static characteristics of Android apps. This thesis focuses on the static analysis of Android apps for the extraction of relevant metrics for malware detection by machine learning.
Quality benchmarks are essential to proposing effective machine learning approaches. Therefore, the work presented in this document first proposes scripts able to apply diverse static analyses on an app and extract a set of metrics inspired by various works in the literature. In addition, we propose on this basis a dataset of more than 17,000 apps for the evaluation of machine learning approaches for Android malware detection.
This thesis also includes machine learning experiments using classification strategies that define the legitimate static characteristics of benign versus malicious applications. Put trivially, benign applications will share similar characteristics, while malicious applications will exhibit anomalous characteristics that ought to be identified. Based on the developed datasets, we propose and test the performance of various classification models in detecting malicious applications.
The tested models include common classifiers, as well as more advanced Support Vector Machine and Deep Learning models, whose hyperparameters have been tuned to improve the accuracy and efficiency of malware detection. Finally, we examined on the basis of Android permissions and security risks, the possible discrepancies between permission usage patterns of benign applications versus malware across different app categories.
Namrud, Z. (Author),
Kpodjedo (Supervisor) &
Talhi (Co-supervisor),
30 Apr 2022Student thesis: Doctoral thesis › Doctorate in Engineering: Engineering