IP Library › Granted Patent US 11,809,557
Granted Patent B2
US 11,809,557 · App. 17/296,892 · Granted Nov 7, 2023

Mobile malicious code classification method based on feature selection and recording medium and device for performing the same

Inventors: Jeong Hyun Yi (Seoul, KR); Eun Byeol Ko (Seoul, KR)
Assignee: FOUNDATION OF SOONGSIL UNIVERSITY-INDUSTRY COOPERATION
G06F21/562G06N3/08G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,809,557
App. No.
17/296,892
Granted
Nov 7, 2023
Kind
B2
Abstract

A mobile malicious code classification method based on feature selection includes extracting Application Programming Interface (API) feature information including a package name, a class name, a method name and a description from a malicious application of a predefined category, vectorizing a training dataset generated using the package name, the class name and the method name in the API feature information for deep learning, learning the vectorized training dataset to generate a classifier, probabilistically classifying to fit a target malicious application into a category, and defining the category of the target malicious application using a result of the classification and outputting a classification important API. Accordingly, it is possible to deal with malicious behaviors of malicious applications quickly and prevent damage caused by the malicious behaviors.

Claims (32)

1. A mobile malicious code classification method based on feature selection, the method comprising:

extracting Application Programming Interface (API) feature information including a package name, a class name, a method name, and a description from a malicious application of a predefined category;

vectorizing a training dataset generated using the package name, the class name, and the method name in the API feature information for deep learning;

learning the vectorized training dataset to generate a classifier;

classifying a target malicious application into a category of malicious application based on probability of fit; and

defining the category of the target malicious application using a result of the classifying and outputting a classification important API.

2. The mobile malicious code classification method of claim 1 , wherein the vectorizing comprises:

constructing the training dataset with a plurality of APIs extracted from a malicious application for each category of malicious application; and

vectorizing the plurality of APIs to use the training dataset as an input value of a deep learning algorithm.

3. The mobile malicious code classification method of claim 1 , wherein the classifying comprises assigning, by the classifier, a probability of fitting the target malicious application into the category for each category of malicious application.

4. The mobile malicious code classification method of claim 3 , wherein the outputting the classification important API comprises:

determining for the target application the category corresponding to a probability value that is larger than a preset threshold among the assigned probabilities for the each category of malicious application as a feature of the target malicious application; and

outputting a preset number of APIs having a greatest influence when the target malicious application is assigned with the probabilities for the each category of malicious application by the classifier.

5. A non-transitory computer-readable storage medium having recorded thereon a computer program for performing a mobile malicious code classification method based on feature selection, the method comprising:

extracting Application Programming Interface (API) feature information including a package name, a class name, a method name, and a description from a malicious application of a predefined category;

vectorizing a training dataset generated using the package name, the class name, and the method name in the API feature information for deep learning;

generating a classifier by learning the vectorized training dataset;

classifying a target malicious application into a category of malicious application based on probability of fit; and

defining the category of the target malicious application using a result of the classifying and outputting a classification important API.

6. A mobile malicious code classification device based on feature selection, the device comprising:

an Application Programming Interface (API) extractor extracting API feature information including a package name, a class name, a method name, and a description from a malicious application of a predefined category;

an API vectorizer vectorizing a training dataset generated using the package name, the class name, and the method name in the API feature information for deep learning;

a learner learning the vectorized training dataset to generate a classifier;

a classifier classifying a target malicious application into a category of malicious application based on probability of fit; and

a feature identifier defining the category of the target malicious application using a result of the classifying and outputting a classification important API.

7. The mobile malicious code classification device of claim 6 , wherein the API vectorizer comprises:

a training dataset generator constructing the training dataset with a plurality of APIs extracted from a malicious application for each category of malicious application; and

an API word embedder vectorizing the plurality of APIs to use the training dataset as an input value of a deep learning algorithm.

8. The mobile malicious code classification device of claim 6 , wherein the classifier comprises a probability evaluator assigning a probability of fitting the target malicious application into the category for each category of malicious application.

9. The mobile malicious code classification device of claim 8 , wherein the feature identifier comprises:

a decision maker determining for the target malicious application, as a feature of the target malicious application, the category corresponding to a probability value that is larger than a preset threshold among the assigned probabilities for the each category of malicious application; and

an important API identifier outputting a preset number of APIs having a greatest influence when the target malicious application is assigned with the probabilities for the each category of malicious application by the classifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2021
From: YI, JEONG HYUN; KO, EUN BYEOL
To: FOUNDATION OF SOONGSIL UNIVERSITY-INDUSTRY COOPERATION
Reel/Frame 056346/0939 →
Priority Claims (1)
KR 10-2020-0161669 · Nov 26, 2020 · national
Continuity (1)
Related Publication 20220179955A1 · Jun 9, 2022