Evaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanism

Abstract With the rise in popularity and usage of Android operating systems, malicious applications are targeted by applying innovative ways and techniques. Today, malware becomes intelligent that uses several ways of obfuscation techniques to hide its functionality and evade anti-malware engines. F...

Full description

Bibliographic Details
Main Authors: Sana Aurangzeb, Muhammad Aleem
Format: Article
Language:English
Published: Nature Portfolio 2023-02-01
Series:Scientific Reports
Online Access:https://doi.org/10.1038/s41598-023-30028-w
_version_ 1797865075363545088
author Sana Aurangzeb
Muhammad Aleem
author_facet Sana Aurangzeb
Muhammad Aleem
author_sort Sana Aurangzeb
collection DOAJ
description Abstract With the rise in popularity and usage of Android operating systems, malicious applications are targeted by applying innovative ways and techniques. Today, malware becomes intelligent that uses several ways of obfuscation techniques to hide its functionality and evade anti-malware engines. For mainstream smartphone users, Android malware poses a severe security danger. An obfuscation approach, however, can produce malware versions that can evade current detection strategies and dramatically lower the detection accuracy. Attempting to identify Android malware obfuscation variations, this paper proposes an approach to address the challenges and issues related to the classification and detection of malicious obfuscated variants. The employed detection and classification scheme uses both static and dynamic analysis using an ensemble voting mechanism. Moreover, this study demonstrates that a small subset of features performs consistently well when they are derived from the basic malware (non-obfuscated), however, after applying a novel feature-based obfuscation approach, the study shows a drastic change indicating the relative importance of these features in obfuscating benign and malware applications. For this purpose, we present a fast, scalable, and accurate mechanism for obfuscated Android malware detection based on the Deep learning algorithm using real and emulator-based platforms. The experiments show that the proposed model detects malware effectively and accurately along with the identification of features that are usually obfuscated by malware attackers.
first_indexed 2024-04-09T23:03:18Z
format Article
id doaj.art-d0b633862ef3499aaeb2c44fd5cb5ac3
institution Directory Open Access Journal
issn 2045-2322
language English
last_indexed 2024-04-09T23:03:18Z
publishDate 2023-02-01
publisher Nature Portfolio
record_format Article
series Scientific Reports
spelling doaj.art-d0b633862ef3499aaeb2c44fd5cb5ac32023-03-22T10:54:19ZengNature PortfolioScientific Reports2045-23222023-02-0113111210.1038/s41598-023-30028-wEvaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanismSana Aurangzeb0Muhammad Aleem1Department of Computer Science, National University of Computer and Emerging Sciences (FAST-NUCES)Department of Computer Science, National University of Computer and Emerging Sciences (FAST-NUCES)Abstract With the rise in popularity and usage of Android operating systems, malicious applications are targeted by applying innovative ways and techniques. Today, malware becomes intelligent that uses several ways of obfuscation techniques to hide its functionality and evade anti-malware engines. For mainstream smartphone users, Android malware poses a severe security danger. An obfuscation approach, however, can produce malware versions that can evade current detection strategies and dramatically lower the detection accuracy. Attempting to identify Android malware obfuscation variations, this paper proposes an approach to address the challenges and issues related to the classification and detection of malicious obfuscated variants. The employed detection and classification scheme uses both static and dynamic analysis using an ensemble voting mechanism. Moreover, this study demonstrates that a small subset of features performs consistently well when they are derived from the basic malware (non-obfuscated), however, after applying a novel feature-based obfuscation approach, the study shows a drastic change indicating the relative importance of these features in obfuscating benign and malware applications. For this purpose, we present a fast, scalable, and accurate mechanism for obfuscated Android malware detection based on the Deep learning algorithm using real and emulator-based platforms. The experiments show that the proposed model detects malware effectively and accurately along with the identification of features that are usually obfuscated by malware attackers.https://doi.org/10.1038/s41598-023-30028-w
spellingShingle Sana Aurangzeb
Muhammad Aleem
Evaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanism
Scientific Reports
title Evaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanism
title_full Evaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanism
title_fullStr Evaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanism
title_full_unstemmed Evaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanism
title_short Evaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanism
title_sort evaluation and classification of obfuscated android malware through deep learning using ensemble voting mechanism
url https://doi.org/10.1038/s41598-023-30028-w
work_keys_str_mv AT sanaaurangzeb evaluationandclassificationofobfuscatedandroidmalwarethroughdeeplearningusingensemblevotingmechanism
AT muhammadaleem evaluationandclassificationofobfuscatedandroidmalwarethroughdeeplearningusingensemblevotingmechanism