پدافند غیرعامل

پدافند غیرعامل

ارائه چارچوب ترکیبی تشخیص بدافزارهای اندرویدی با استفاده از الگوریتم بهینه‌سازی ازدحام ذرات بهبودیافته و ماشین بردار پشتیبان با هسته فازی

نوع مقاله : مقاله پژوهشی

نویسنده
استادیار، گروه علوم کامپیوتر، دانشگاه گلستان، گروه علوم کامپیوتر، گرگان، ایران
چکیده .
این مقاله یک چارچوب ترکیبی نوآورانه برای تشخیص بدافزار اندروید ارائه می‌دهد که یک الگوریتم بهینه‌سازی ازدحام ذرات بهبودیافته (IPSO) را با یک ماشین بردار پشتیبان فازی با هسته (FKSVM) تلفیق می‌کند. هدف اصلی، غلبه بر چالش‌های روش‌های سنتی، از جمله ابعاد بالای ویژگی‌ها، همگرایی زودرس و ناتوانی در مدل‌سازی عدم قطعیت ذاتی در داده‌های بدافزاری است. الگوریتم IPSO با بهره‌گیری از یک وزن پویا و یک عملگر جهش تصادفی، از همگرایی زودرس جلوگیری کرده و یک زیرمجموعه ویژگی بهینه را انتخاب می‌کند. در ادامه، مدل FKSVM با استفاده از یک هسته فازی جدید، عدم قطعیت داده‌ها را به طور مؤثر مدیریت می‌نماید. ارزیابی چارچوب پیشنهادی بر روی مجموعه‌داده CIC-AndMal2020 نشان می‌دهد که این روش در طبقه‌بندی دودویی به دقت ۹۹.۹۸ درصد و نرخ هشدار نادرست بسیار پایین ۰.۰۱ درصد دست می‌یابد. این نتایج، عملکرد برتر چارچوب ارائه‌شده را در مقایسه با روش‌های موجود از نظر دقت، سرعت و مقاومت در برابر حملات متخاصم به وضوح نشان می‌دهد و اثربخشی آن را تأیید می‌کند.
کلیدواژه‌ها

عنوان مقاله English

A Hybrid Framework for Android Malware Detection Using an Improved Particle Swarm Optimization and Fuzzy Kernel Support Vector Machine

نویسنده English

Aliakbar Tajari Siahmarzkooh
Assistant Professor, Department of Computer Science, Golestan University, Gorgan, Iran
چکیده . English

This paper presents a novel hybrid framework for Android malware detection that integrates an Improved Particle Swarm Optimization (IPSO) algorithm with a Fuzzy Kernel Support Vector Machine (FKSVM). The primary objective is to overcome the challenges of traditional methods, including high feature dimensionality, premature convergence, and the inability to model the inherent uncertainty in malware data. The IPSO algorithm, leveraging a dynamic inertia weight and a random mutation operator, prevents premature convergence and selects an optimal feature subset. Subsequently, the FKSVM model effectively manages data uncertainty through a novel fuzzy kernel. Evaluation of the proposed framework on the CIC-AndMal2020 dataset demonstrates that the method achieves a binary classification accuracy of 99.98% and an extremely low false alarm rate of 0.01%. These results clearly indicate the superior performance of the proposed framework compared to existing methods in terms of accuracy, speed, and robustness against adversarial attacks, thereby confirming its effectiveness.

کلیدواژه‌ها English

Malware Detection
Android
Particle Swarm Optimization
Support Vector Machine
Fuzzy Kernel
Feature Selection
[1]   A. Khosravi and M. A. Javadzade, Reducing Cyber Risks in the Internet of Things Using Hybrid Graph and Behavioral Deep Learning Models,” Passive Defense, vol. 16(3), pp. 55-62, 2025 (In Persian).
[2]   A. Mohtarami, and A. Jamshidi, “Providing a Framework of Solutions to Reduce the Vulnerability of Smart Cards,” Passive Defense, vol. 15(3), pp. 85-95, 2025 (In Persian).
[3]   H. Tabatabaee, and S. Hadavi, “Feature selection and intrusion detection in wireless sensor networks with Unsupervised Extreme Learning Machine (UELM),” Passive Defense, vol. 15(4), pp. 25-40, 2025 (In Persian).
[4]   A. Ghasemi, M. Fathi, and A. Hamzeh, “A Novel Hybrid Approach for Android Malware Detection Based on Deep Learning and Ensemble Methods,” Electrical and Computer Engineering Innovations Journal, vol. 10(2), pp. 89-102, 2022 (In Persian).
[5]   D. Arp, M. Spreitzenbarth, M. Hübner, H. Gascon, and K. Rieck, “DREBIN: Effective and Explainable Detection of Android Malware in Your Pocket,” In Proceedings of the Network and Distributed System Security Symposium (NDSS), 2014.
[6]   M. Milani, A. Ghasemi, and S. E. Alavi, “Android Malware Detection Using Random Forest Classifier,” IEEE Access, vol. 7(2), pp. 145145-145155, 2019.
[7]   L. Chen, Y. Wang, and J. Zhang, “A GA-Based Feature Selection Approach for Android Malware Detection,” Journal of Network and Computer Applications, vol. 163(3), 102678, 2020.
[8]   Y. Liu, H. Zhang, and X. Li, Particle Swarm Optimization for Feature Selection in Android Malware Detection,” Expert Systems with Applications, vol. 168(1), 114258, 2021.
[9]   S. Wu, P. Wang, and Y. Zhou, “1D-CNN for Android Malware Detection Based on Opcode Sequences,” Computers & Security, vol. 113(3), 102549, 2021.
[10] H. Zhang, J. Li, and B. Chen, “Dynamic Android Malware Detection Using LSTM on System Call Sequences,” IEEE Transactions on Information Forensics and Security, vol. 16(3), pp. 2450-2463, 2021.
[11] M. Alizadeh, S. Mohammadi, and M. Rezaei, “A Fuzzy Inference System for Android Malware Detection,” International Journal of Fuzzy Systems, vol. 21(5), pp. 1421-1433, 2019.
 
 
 
 
 
 
 
 
 
 
 
 
[12] J. Wang, T. Liu, and K. Yang, “Artificial Bee Colony based Feature Selection for SVM in Android Malware Detection,” Soft Computing, vol. 24(14), pp. 10667-10679, 2021.
[13] I. G. W., Dharma, A. Wibowo, and R. F. Sari, “Grey Wolf Optimizer for Feature Selection in Android Malware Analysis,” Neural Computing and Applications, vol. 34(12), pp. 10245-10258, 2022.
[14] X. Li, Y. Zhang, and Z. Wang, “A Novel Hybrid Kernel SVM for Android Malware Classification,” Knowledge-Based Systems, vol. 218(2), pp. 106845, 2021.
[15] P. Smith, and R. Johnson, “Anomaly-Based Android Malware Detection Using RBF-SVM,” Journal of Information Security and Applications, vol. 46(3), pp. 44-52, 2019.
[16] S. Garcia, C. Martinez, and F. Rodriguez, “A Hybrid CNN-LSTM Model for Advanced Android Malware Detection,” IEEE Transactions on Dependable and Secure Computing, vol. 20(1), pp. 123-136, 2023.
[17] T. Kim, S. Park, and J. Lee, “BERT-based Assembly Code Analysis for Android Malware Detection,” In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2022.
[18] Canadian Institute for Cybersecurity (CIC). (2020). CICAndMal2020 Dataset. Retrieved from https://www.unb.ca/cic/datasets/andmal2020.html.
[19] S. García, J. Luengo, and F. Herrera, “Data Preprocessing in Data Mining,” Springer Book Series., 2015.
[20] J. Kennedy, and R. Eberhart, “Particle Swarm Optimization,” “In Proceedings of ICNN'95 - International Conference on Neural Networks,” vol. 4(2), pp. 1942-1948, 1995.
[21] L. A. Zadeh, “Fuzzy Sets. Information and Control,” vol. 8(3), pp. 338-353, 1965.
[22] M. Sokolova, and G. Lapalme, “A systematic analysis of performance measures for classification tasks,” Information Processing & Management, vol. 45(4), pp. 427-437, 1995.
[23] C. Cortes, and V. Vapnik, “Support-vector networks,” Machine Learning, vol. 20(3), pp. 273-297, 1995.
[24] L. Breiman, “Random Forests,” Machine Learning, vol. 45(1), pp. 5-32, 2001.
[25] I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” arXiv preprint arXiv:1412.6572, 2014.
[26] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” arXiv preprint arXiv:1706.06083, 2017.
[27] G. H. Lai, C. Chen, B. Chiang Jeng, and W. Chao, “Ant-based IP traceback,” Expert Systems with Applications, vol. 34(3), pp. 3071-3080, 2008.
دوره 17، شماره 2 - شماره پیاپی 66
شماره پیا پی 66 تابستان 1405
تابستان 1405
صفحه 75-90

  • تاریخ دریافت 16 مهر 1404
  • تاریخ بازنگری 14 دی 1404
  • تاریخ پذیرش 22 تیر 1405
  • تاریخ انتشار 01 مرداد 1405