AI-driven Threat Detection and Prevention for Android Security: A Simulation-based Approach usingReal-World Datasets
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE credits
Student thesis
Abstract [en]
We present Android Guardian, our novel machine learning driven framework for detecting Android malware that exploits inter-component communication (ICC) vulnerabilities, namely, intent hijacking, content provider misuse, and side-channel data leakage. By unifying static and dynamic analysis within a deployment-feasible design, Android Guardian addresses limitations of prior methods that treat these analyses in isolation, often overlooking real-world resource constraints. On the static analysis side, we built a bespoke dataset of 35,000 APKs from AndroZoo, extracting over 80 engineered features (API usage patterns, permissions, intent filters, ICC component attributes) via Androguard and MobSF–guided logic. We devised a custom rule-based labeling system, grounded in Common Weakness Enumerations (CWE) and the OWASP Mobile Top 10, to categorize malicious apps into intent hijacking, content provider exploitation, or side-channel leakage. A two-stage XGBoost pipeline then achieves 97% binary classification accuracy and 97.7% multi-class accuracy, with SHAP explainability confirming feature value. For dynamic analysis, Android Guardian introduces (1) a flow-level detector leveraging engineered NetFlow statistics, and (2) an APK-level aggregation approach that condenses runtime behavior into compact vectors. Evaluated on CICAndMal2017 and NS-3 simulated traffic, the APK-level model reaching 94.8% accuracy and an F1-score of 0.88, outperforming existing baselines. Implications: By delivering a modular, interpretable solution, Android Guardian aids security researchers in exploring ICC threats, helps mobile developers harden apps against inter-component exploits, and supports security professionals in integrating advanced detection into antivirus engines, enterprise threat-monitoring platforms, or app-store vetting workflows. Although tailored to Android, our dynamic traffic-based techniques are readily adaptable to other mobile ecosystems, offering a path toward cross-platform malware defense.
Place, publisher, year, edition, pages
2025. , p. 62
Keywords [en]
Android, ICC, Machine Learning, XGBoost, IAC
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:hv:diva-23726Local ID: EXD600OAI: oai:DiVA.org:hv-23726DiVA, id: diva2:1981487
Subject / course
Computer engineering
Educational program
Master in Cybersecurity
Supervisors
Examiners
2025-07-212025-07-042025-09-30Bibliographically approved