计算机科学
恶意软件
Android(操作系统)
Android恶意软件
许可
依赖关系图
特征学习
静态分析
图形
恶意软件分析
机器学习
人工智能
理论计算机科学
抽象
移动设备
系统调用
调用图
代表(政治)
数据挖掘
特征提取
功率图分析
特征(语言学)
聚类分析
知识图
作者
Zhichao Shi,Qiang Han,Zihao Zhang
标识
DOI:10.1109/apsec66846.2025.00078
摘要
Android malware detection has become increasingly critical as mobile applications continue to proliferate. Traditional detection methods primarily rely on static analysis of permissions and API calls, but often fail to capture the complex behavioral patterns and contextual relationships inherent in malicious applications. To address this limitation, we introduce Chain of Command, a novel framework centered on the Permission-to-API Call Chain (PACC). A PACC represents a complete execution path from an application entry point to a sensitive API invocation, effectively preserving the contextual link between a required permission and its use. Our methodology comprises three stages: first, extracting PACCs through a backward analysis of the application’s call graph; second, performing semantic abstraction to map concrete method signatures to generalized behavioral categories; and third, constructing a compact behavior graph from these abstracted chains, which is then classified using a Graph Attention Network (GAT). Evaluation on a large-scale Android dataset demonstrates that our framework significantly outperforms state-of-the-art methods in both accuracy and robustness. Our findings underscore the efficacy of integrating contextual feature engineering, semantic abstraction, and graph representation learning for developing more reliable and interpretable malware detection systems.
科研通智能强力驱动
Strongly Powered by AbleSci AI