Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
AI-driven Threat Detection and Prevention for Android Security: A Simulation-based Approach usingReal-World Datasets
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

We present Android Guardian, our novel machine learning driven framework for detecting Android malware that exploits inter-component communication (ICC) vulnerabilities, namely, intent hijacking, content provider misuse, and side-channel data leakage. By unifying static and dynamic analysis within a deployment-feasible design, Android Guardian addresses limitations of prior methods that treat these analyses in isolation, often overlooking real-world resource constraints. On the static analysis side, we built a bespoke dataset of 35,000 APKs from AndroZoo, extracting over 80 engineered features (API usage patterns, permissions, intent filters, ICC component attributes) via Androguard and MobSF–guided logic. We devised a custom rule-based labeling system, grounded in Common Weakness Enumerations (CWE) and the OWASP Mobile Top 10, to categorize malicious apps into intent hijacking, content provider exploitation, or side-channel leakage. A two-stage XGBoost pipeline then achieves 97% binary classification accuracy and 97.7% multi-class accuracy, with SHAP explainability confirming feature value. For dynamic analysis, Android Guardian introduces (1) a flow-level detector leveraging engineered NetFlow statistics, and (2) an APK-level aggregation approach that condenses runtime behavior into compact vectors. Evaluated on CICAndMal2017 and NS-3 simulated traffic, the APK-level model reaching 94.8% accuracy and an F1-score of 0.88, outperforming existing baselines. Implications: By delivering a modular, interpretable solution, Android Guardian aids security researchers in exploring ICC threats, helps mobile developers harden apps against inter-component exploits, and supports security professionals in integrating advanced detection into antivirus engines, enterprise threat-monitoring platforms, or app-store vetting workflows. Although tailored to Android, our dynamic traffic-based techniques are readily adaptable to other mobile ecosystems, offering a path toward cross-platform malware defense.

Place, publisher, year, edition, pages
2025. , p. 62
Keywords [en]
Android, ICC, Machine Learning, XGBoost, IAC
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:hv:diva-23726Local ID: EXD600OAI: oai:DiVA.org:hv-23726DiVA, id: diva2:1981487
Subject / course
Computer engineering
Educational program
Master in Cybersecurity
Supervisors
Examiners
Available from: 2025-07-21 Created: 2025-07-04 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Engineering Science
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 662 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf