{"id":"https://openalex.org/W2902979785","doi":"https://doi.org/10.1145/3274694.3274744","title":"Improving Accuracy of Android Malware Detection with Lightweight Contextual Awareness","display_name":"Improving Accuracy of Android Malware Detection with Lightweight Contextual Awareness","publication_year":2018,"publication_date":"2018-12-03","ids":{"openalex":"https://openalex.org/W2902979785","doi":"https://doi.org/10.1145/3274694.3274744","mag":"2902979785"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3274694.3274744","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5007487580","display_name":"Joey Allen","orcid":"https://orcid.org/0000-0002-5503-4123"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Joey Allen","raw_affiliation_strings":["Georgia Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053937867","display_name":"Matthew Landen","orcid":"https://orcid.org/0000-0003-3095-1619"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Matthew Landen","raw_affiliation_strings":["Georgia Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020206458","display_name":"Sanya Chaba","orcid":null},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sanya Chaba","raw_affiliation_strings":["Georgia Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045154172","display_name":"Ji Yang","orcid":"https://orcid.org/0000-0002-5209-7436"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yang Ji","raw_affiliation_strings":["Georgia Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052526223","display_name":"Simon P. Chung","orcid":null},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Simon Pak Ho Chung","raw_affiliation_strings":["Georgia Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5047140382","display_name":"Wenke Lee","orcid":"https://orcid.org/0000-0003-2761-1277"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wenke Lee","raw_affiliation_strings":["Georgia Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology","institution_ids":["https://openalex.org/I130701444"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":3.037,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":30,"citation_normalized_percentile":{"value":0.999569,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":93,"max":94},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.994,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9915,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/android-malware","display_name":"Android Malware","score":0.75092876},{"id":"https://openalex.org/keywords/invocation","display_name":"Invocation","score":0.44437993}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8709389},{"id":"https://openalex.org/C2989133298","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android malware","level":3,"score":0.75092876},{"id":"https://openalex.org/C55439883","wikidata":"https://www.wikidata.org/wiki/Q360812","display_name":"Correctness","level":2,"score":0.7046641},{"id":"https://openalex.org/C93518851","wikidata":"https://www.wikidata.org/wiki/Q180160","display_name":"Metadata","level":2,"score":0.61318904},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.57491505},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5264469},{"id":"https://openalex.org/C27158222","wikidata":"https://www.wikidata.org/wiki/Q5532422","display_name":"Generalizability theory","level":2,"score":0.52618396},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.50479376},{"id":"https://openalex.org/C2776527387","wikidata":"https://www.wikidata.org/wiki/Q1671839","display_name":"Invocation","level":2,"score":0.44437993},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.40866596},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.37118047},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.1369384},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.10309371},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.10159677},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.08496395},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0},{"id":"https://openalex.org/C19165224","wikidata":"https://www.wikidata.org/wiki/Q23404","display_name":"Anthropology","level":1,"score":0.0},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3274694.3274744","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.71,"display_name":"Peace, justice, and strong institutions","id":"https://metadata.un.org/sdg/16"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":45,"referenced_works":["https://openalex.org/W1445387515","https://openalex.org/W1630356589","https://openalex.org/W1647869403","https://openalex.org/W1865564993","https://openalex.org/W1943233084","https://openalex.org/W1963971515","https://openalex.org/W1979628629","https://openalex.org/W1982773740","https://openalex.org/W1985752637","https://openalex.org/W2000730583","https://openalex.org/W2003276999","https://openalex.org/W2041276426","https://openalex.org/W2047028564","https://openalex.org/W2068731595","https://openalex.org/W2070386561","https://openalex.org/W2071536101","https://openalex.org/W2072391287","https://openalex.org/W2078197322","https://openalex.org/W2101234009","https://openalex.org/W2114275288","https://openalex.org/W2122672392","https://openalex.org/W2125011234","https://openalex.org/W2127723417","https://openalex.org/W2140095007","https://openalex.org/W2141278204","https://openalex.org/W2152149943","https://openalex.org/W2168103835","https://openalex.org/W2168649891","https://openalex.org/W2220697891","https://openalex.org/W2291203434","https://openalex.org/W2399891510","https://openalex.org/W2407059953","https://openalex.org/W2407313496","https://openalex.org/W2487124337","https://openalex.org/W2513201734","https://openalex.org/W2571682498","https://openalex.org/W2585223762","https://openalex.org/W2613948935","https://openalex.org/W273955616","https://openalex.org/W2753594008","https://openalex.org/W2775261393","https://openalex.org/W2792393499","https://openalex.org/W2793024489","https://openalex.org/W2794510434","https://openalex.org/W4239277337"],"related_works":["https://openalex.org/W4312334973","https://openalex.org/W4311848503","https://openalex.org/W4249118297","https://openalex.org/W3200508744","https://openalex.org/W3025122950","https://openalex.org/W2782775281","https://openalex.org/W2717179875","https://openalex.org/W2591124010","https://openalex.org/W2560361988","https://openalex.org/W2507113366"],"abstract_inverted_index":{"In":[0,46,190],"Android":[1],"malware":[2],"detection,":[3],"recent":[4],"work":[5],"has":[6,72,113],"shown":[7],"that":[8,69,76,107,146,195],"using":[9,58],"contextual":[10,60],"information":[11,40,61,71],"of":[12,19,57,80,92,110,167,178,208,215,223],"sensitive":[13,180],"API":[14,111,150],"invocation":[15,112,151],"in":[16,43,62,155],"the":[17,25,29,44,55,59,85,88,93,98,102,108,114,118,125,149,156,160,175,191,201],"modeling":[18],"applications":[20,210],"is":[21,41],"able":[22],"to":[23,171],"improve":[24,124],"classification":[26,119,188],"accuracy.":[27,100],"However,":[28],"improvement":[30],"brought":[31],"by":[32,211],"this":[33,39,47,70,133,196],"context-awareness":[34],"varies":[35],"depending":[36],"on":[37,54,117,132,204],"how":[38],"used":[42],"modeling.":[45,157],"paper,":[48],"we":[49,105,135,193],"perform":[50],"a":[51,77,139,165,179,184,205,219],"comprehensive":[52],"study":[53],"effectiveness":[56],"prior":[63],"state-of-the-art":[64],"detection":[65,99,142,202],"systems.":[66],"We":[67],"find":[68,106],"been":[73],"\"over-used\"":[74],"such":[75],"large":[78],"amount":[79],"non-essential":[81],"metadata":[82],"built":[83],"into":[84],"models":[86],"weakens":[87],"generalizability":[89],"and":[90,137,152,173],"longevity":[91],"model,":[94],"thus":[95],"finally":[96],"affects":[97],"On":[101],"other":[103],"hand,":[104],"entrypoint":[109,154],"strongest":[115],"impact":[116],"correctness,":[120],"which":[121],"can":[122],"further":[123],"accuracy":[126,203],"if":[127],"being":[128],"properly":[129],"captured.":[130],"Based":[131],"finding,":[134],"design":[136],"implement":[138],"lightweight,":[140],"circumstance-aware":[141],"system,":[143],"named":[144],"\"PIKADROID\"":[145],"only":[147],"uses":[148],"its":[153],"For":[158],"extracting":[159],"meaningful":[161],"entrypoints,":[162],"PIKADROID":[163],"applies":[164],"set":[166,207],"static":[168],"analysis":[169],"techniques":[170],"extract":[172],"sanitize":[174],"reachable":[176],"entrypoints":[177],"API,":[181],"then":[182],"constructs":[183],"frequency":[185],"model":[186,198],"for":[187],"decision.":[189],"evaluation,":[192],"show":[194],"slim":[197],"significantly":[199],"improves":[200],"data":[206],"23,631":[209],"achieving":[212],"an":[213],"f-score":[214],"97.41%,":[216],"while":[217],"maintaining":[218],"false":[220],"positive":[221],"rating":[222],"0.96%.":[224]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2902979785","counts_by_year":[{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":10},{"year":2020,"cited_by_count":7},{"year":2019,"cited_by_count":4},{"year":2018,"cited_by_count":1}],"updated_date":"2025-01-07T12:57:14.456538","created_date":"2018-12-11"}