Repository for the code developed in the context of my thesis entitled "Malware Detection in Android Applications with Machine Learning Techniques" for the MSc in Computer Science and Engineering at Lisbon Institute of Engineering (ISEL). The thesis was developed under the guidance of Professor Artur Ferreira.
The dissertation is available here.
The presence of malicious software (malware), for example, in Android applications (apps), has harmful or irreparable consequences to the user and/or the device. Despite the protections app stores provide to restrict apps containing malware, it keeps growing in sophistication and diffusion.
In this thesis, a prototype that resorts to Machine Learning (ML) techniques to detect malware in Android applications was developed. Different data pre-processing, dimensionality reduction, and classification techniques were applied, assessing the generalisation ability of the learned models using public domain datasets. Emphasises was given to Feature Selection (FS), which reduces the data’s dimensionality and identifies the most relevant features in Android malware classification.
From this thesis, the following papers have been published.
-
Catarina Palma, Artur Ferreira, and Mário Figueiredo, "On the use of machine learning techniques to detect malware in mobile applications", Simpósio em Informática (INForum), September 2023, Porto, Portugal. Also available on ResearchGate.
-
Catarina Palma, Artur Ferreira, and Mário Figueiredo, "A study on the role of feature selection for malware detection on Android applications", Portuguese Conference on Pattern Recognition (RECPAD), October 2023, Coimbra, Portugal. Also available on ResearchGate.
-
Catarina Palma, Artur Ferreira, and Mário Figueiredo, "Explainable Machine Learning for Malware Detection on Android Applications", Information journal, MDPI, January 2024. Also available on ResearchGate.
The problem is formulated as a binary classification problem. The aim is to classify a given Android application as malicious (positive) or benign (negative). Each component integrating the proposed approach or enabling its assessment is briefly described next.
Machine Learning module - Component responsible for building, improving and evaluating the ML model that will classify Android applications as benign or malicious.
Feature extraction module - Extracts static features from an Android application’s Android Package Kit (APK) file. It maps them with the features deemed more relevant of the presence of malware in Android applications. This mapping results in the input data provided to the model, which can then classify/predict the Android application as benign or malicious.
Android applications - Allow an assessment of the developed prototype with real-world apps.
Public domain datasets were used in the development and assessment of the prototype of the proposed approach.
Software tools used in the development and assessment of the proposed approach's prototype.
Note: The requirements.txt file specifies the dependencies required to run this project. You can use it to set up the same dependencies.

