Knowledge Is Power: a Knowledge Graph-Based Approach for Mobile Malware Traceability Analysis
IEEE transactions on mobile computing, Vol.First online(8), pp.1-17
16/03/2026
5
The prevalence of Android malware has brought forth the issue of traceability in malware analysis, prompting the need for exploration. Establishing connections between newly discovered malware and existing data can shed light on the traceability analysis and underlying reasons behind the malware. However, real-world analysis of malware traceability is intricate and time-consuming due to the vast volume of data, often requiring manual examination and lacking explanatory results. Hence, a comprehensive automated malware tracing framework is urgently needed to provide detailed insights into traceability identification and explanatory capabilities. This paper introduces a knowledge graph-based approach utilizing partial API call graphs with semantic and behavioral features to uncover traceability relations among malware and generate explainable results. The approach is based on a dataset comprising over 20,000 labeled malware samples from a decade, addressing complexity through prior knowledge utilization and a branch pruning method for call graphs. This reduces com putational complexity and enhances precision in determining traceability relations. Rigorous evaluation and validation were conducted, assessing the system's effectiveness in tracking mal ware through extensive experiments and results confirmation with further analysis. The system's ability is validated by effectiveness, soundness, and practicality to demonstrate the value of approach design and its real-world applicability for security professionals.
- Knowledge Is Power: a Knowledge Graph-Based Approach for Mobile Malware Traceability Analysis
- Yao Zhang - Tianjin UniversityGuangquan Xu - Tianjin UniversityRuitao Feng - Southern Cross UniversityXiaohong Li - Tianjin UniversitySen Chen - Nankai UniversityZhenchang Xing - Australian National UniversityYude Bai - Tiangong UniversityYongqiang Lyu - Tianjin UniversityWei Gong - University of Science and Technology of ChinaXibin Zhao - Tsinghua University
- IEEE transactions on mobile computing, Vol.First online(8), pp.1-17
- IEEE
- National Natural Science Foundation of China: U22B2027, 62332005, U24A6009, U2436208, 62272311, 62172297 Beijing-Tianjin-Hebei Natural Science Foundation Cooperation Special Project: 25JJJJC0034 Joint Research Center for System Security, Tsinghua University (Institute for Network Sciences and Cyberspace) Science City (Guangzhou) Digital Technology Group Company, Ltd.
This work was supported in part by the National Natural Science Foundation of China under Grant U22B2027, Grant 62332005, Grant U24A6009, Grant U2436208, Grant 62272311, and Grant 62172297, in part by Beijing-Tianjin-Hebei Natural Science Foundation Cooperation Special Project under Grant 25JJJJC0034, in part by Joint Research Center for System Security, Tsinghua University (Institute for Network Sciences and Cyberspace), and in part by Science City (Guangzhou) Digital Technology Group Company, Ltd. Recommended for acceptance by T. X. Han. (Yao Zhang and Guangquan Xu contributed equally to this work.)
- 991013372751502368
- Faculty of Science and Engineering
- English
- Journal article