Home / Current Issue / Paper 1716219
Android Malware Detection Using Permission-Based Static Analysis and Machine Learning
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
DOI: 10.64388/IREV9I10-1716219
Abstract
The Rapid Growth Of Android Applications Has Significantly Increased The Risk Of Malicious Software Targeting Mobile Users. Traditional Signature-Based Detection Methods Fail To Identify Newly Emerging And Obfuscated Malware. This Paper Presents A Permission-Based Static Analysis Approach For An- Droid Malware Detection Using Machine Learning Techniques. The System Extracts Declared Permissions From Apk Files Using The Androguard Framework And Converts Them Into Binary Feature Vectors. A Random Forest Classifier Is Trained Using An 80–20 Train-Test Split To Classify Applications As Benign Or Malicious. Performance Metrics Including Accuracy, Precision, Recall, F1- Score, And Confusion Matrix Are Evaluated. The System Also Includes A Heuristic Fallback Mechanism Based On Dangerous Permission Thresholds. Experimental Results Demonstrate That Permission-Based Static Analysis Combined With Machine Learning Provides An Efficient And Scalable Approach For Preliminary Android Malware Detection.
Keywords
Android Malware, Static Analysis, Machine Learning, Random Forest, Androguard, Cybersecurity
References
[1] D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon, and K. Rieck, “Drebin: Effective and explainable detection of Android malware in your pocket,” in Proc. NDSS Symp., 2014.
[2] Y. Zhou and X. Jiang, “Dissecting Android malware: Characterization and evolution,” in Proc. IEEE Symp. Security and Privacy, 2012, pp. 95–109.
[3] S. Yerima, S. Sezer, and I. Muttik, “High accuracy Android malware detection using ensemble learning,” IET Inf. Security, vol. 9, no. 6, pp. 313–320, 2015.
[4] N. Alzaylaee, S. Yerima, and S. Sezer, “DL- Droid: Deep learning based Android malware detection using real devices,” Comput. Security, vol. 89, 2020.
[5] A. Feizollah, N. Anuar, R. Salleh, and A. Wahab, “AndroDialysis: Analysis of Android intent effectiveness in malware detection,” Comput. Security, vol. 65, pp. 121–134, 2017.
[6] W. Enck et al., “TaintDroid: An information- flow tracking system for realtime privacy monitoring on smartphones,” in Proc. OSDI, 2010, pp. 393–407.
[7] S. Aafer, W. Du, and H. Yin, “DroidAPIMiner: Mining API-level features for robust malware detection in Android,” in Proc. SecureComm, 2013, pp. 86–103.
[8] A. Shabtai, U. Kanonov, Y. Elovici, C. Glezer, and Y. Weiss, “Andro- maly: A behavioral malware detection framework for Android devices,” J. Intell. Inf. Syst., vol. 38, no. 1, pp. 161–190, 2012.
[9] K. Tam, S. Khan, A. Fattori, and L. Cavallaro, “CopperDroid: Automatic reconstruction of Android malware behaviors,” in Proc. NDSS, 2015.
[10] J. Sahs and L. Khan, “A machine learning approach to Android malware detection,” in Proc. IEEE Intell. Security Inform., 2012, pp. 141–147.
[11] H. Peng et al., “Using probabilistic generative models for ranking risks of Android apps,” in Proc. ACM CCS, 2012, pp. 241–252.
[12] Z. Yuan, Y. Lu, and Y. Xue, “Droiddetector: Android malware charac- terization and detection using deep learning,” Tsinghua Sci. Technol., vol. 21, no. 1, pp. 114–123, 2016.
[13] M. Lindorfer, M. Neugschwandtner, and C. Platzer, “MARVIN: Efficient and comprehensive mobile app classification through static and dynamic analysis,” in Proc. COMPSAC, 2015, pp. 422–433.
[14] K. Allix, T. Bissyande, J. Klein, and Y. Le Traon, “AndroZoo: Collecting millions of Android apps for the research community,” in Proc. MSR, 2016, pp. 468–471.
[15] M. Grace, Y. Zhou, Q. Zhang, S. Zou, and X. Jiang, “RiskRanker: Scalable and accurate zero-day Android malware detection,” in Proc. MobiSys, 2012, pp. 281–294.
[16] H. Gascon, F. Yamaguchi, D. Arp, and K. Rieck, “Structural detection of Android malware using embedded call graphs,” in Proc. AISec, 2013, pp. 45–54.
[17] X. Su, D. Zhang, W. Li, and K. Zhao, “A deep learning approach to Android malware feature learning and detection,” in Proc. IEEE TrustCom, 2016, pp. 44–51.
[18] A. Mahindru and P. Singh, “Dynamic permissions based Android malware detection using machine learning techniques,” in Proc. NGCT, 2017, pp. 202–208.
[19] S. Wang, Z. Chen, Q. Yan, B. Yang, L. Peng, and Z. Jia, “A mobile malware detection method using behavior features in network traffic,” J. Netw. Comput. Appl., vol. 133, pp. 15–25, 2019.
How to cite this paper
@article{1716219,
author = {G. Prajith, A. Rakesh Kanna, T. Tarun Kumar, M. Janu},
title = {Android Malware Detection Using Permission-Based Static Analysis and Machine Learning},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {9},
number = {10},
pages = {1278-1285},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1716219.pdf},
abstract = {The Rapid Growth Of Android Applications Has Significantly Increased The Risk Of Malicious Software Targeting Mobile Users. Traditional Signature-Based Detection Methods Fail To Identify Newly Emerging And Obfuscated Malware. This Paper Presents A Permission-Based Static Analysis Approach For An- Droid Malware Detection Using Machine Learning Techniques. The System Extracts Declared Permissions From Apk Files Using The Androguard Framework And Converts Them Into Binary Feature Vectors. A Random Forest Classifier Is Trained Using An 80–20 Train-Test Split To Classify Applications As Benign Or Malicious. Performance Metrics Including Accuracy, Precision, Recall, F1- Score, And Confusion Matrix Are Evaluated. The System Also Includes A Heuristic Fallback Mechanism Based On Dangerous Permission Thresholds. Experimental Results Demonstrate That Permission-Based Static Analysis Combined With Machine Learning Provides An Efficient And Scalable Approach For Preliminary Android Malware Detection.},
keywords = {Android Malware, Static Analysis, Machine Learning, Random Forest, Androguard, Cybersecurity},
month = {April},
doi = {https://doi.org/10.64388/IREV9I10-1716219}
}