{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,4]],"date-time":"2025-07-04T04:08:37Z","timestamp":1751602117883,"version":"3.41.0"},"publisher-location":"Cham","reference-count":51,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319788128"},{"type":"electronic","value":"9783319788135"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-78813-5_23","type":"book-chapter","created":{"date-parts":[[2018,4,10]],"date-time":"2018-04-10T10:03:21Z","timestamp":1523354601000},"page":"449-468","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Visual Analysis of Android Malware Behavior Profile Based on $$PMCG_{droid}$$ : A\u00a0Pruned Lightweight APP Call Graph"],"prefix":"10.1007","author":[{"given":"Yan","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gui","family":"Peng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lu","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yazhe","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Minghui","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianxing","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liming","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chen","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,4,11]]},"reference":[{"key":"23_CR1","doi-asserted-by":"crossref","unstructured":"Beresford, A.R., Rice, A., Skehin, N., Sohan, R.: MockDroid: trading privacy for application functionality on smartphones. In: 12th Workshop on Mobile Computing Systems and Applications, pp. 49\u201354. ACM (2011)","DOI":"10.1145\/2184489.2184500"},{"key":"23_CR2","unstructured":"Octeau, D., McDaniel, P., Jha, S., Bartel, A., Bodden, E., Klein, J., Le Traon, Y.: Effective inter-component communication mapping in android with epicc: an essential step towards holistic security analysis. In: 22nd USENIX Security Symposium, pp. 543\u2013558. USENIX (2013)"},{"key":"23_CR3","unstructured":"Zhou, Y., Wang, Z., Zhou, W., Jiang, X.: Hey, you, get off of my market: detecting malicious apps in official and alternative android markets. In: NDSS, pp. 50\u201352. NDSS (2012)"},{"key":"23_CR4","doi-asserted-by":"crossref","unstructured":"Enck, W., Ongtang, M., McDaniel, P.: On lightweight mobile phone application certification. In: 16th ACM Conference on Computer and Communications Security, pp. 235\u2013245. ACM (2009)","DOI":"10.1145\/1653662.1653691"},{"key":"23_CR5","doi-asserted-by":"crossref","unstructured":"Sun, M., Wei, T., Lui, J.: Taintart: a practical multi-level information-flow tracking system for android runtime. In: 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 331\u2013342. ACM (2016)","DOI":"10.1145\/2976749.2978343"},{"key":"23_CR6","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1007\/978-3-642-33018-6_30","volume-title":"Advances in Intelligent Systems and Computing","author":"B Sanz","year":"2013","unstructured":"Sanz, B., Santos, I., Laorden, C., Ugarte-Pedrero, X., Bringas, P.G., \u00c1lvarez, G.: PUMA: permission usage to detect malware in android. In: Herrero, \u00c1., et al. (eds.) Advances in Intelligent Systems and Computing, vol. 189, pp. 289\u2013298. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-33018-6_30"},{"key":"23_CR7","doi-asserted-by":"crossref","unstructured":"Acar, Y., Backes, M., Bugiel, S., Fahl, S., McDaniel, P., Smith, M.: SoK: lessons learned from android security research for appified software platforms. In: Security and Privacy IEEE, pp. 433\u2013451 (2016)","DOI":"10.1109\/SP.2016.33"},{"key":"23_CR8","doi-asserted-by":"crossref","unstructured":"Arp, D., Gascon, H., Rieck, K., Spreitzenbarth, M., Hbner, M.: DREBIN: effective and explainable detection of android malware in your pocket. In: NDSS. NDSS (2014)","DOI":"10.14722\/ndss.2014.23247"},{"issue":"6","key":"23_CR9","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1145\/2666356.2594299","volume":"49","author":"Steven Arzt","year":"2014","unstructured":"Arzt, S., Rasthofer, S., Fritz, C., Bodden, E., Bartel, A., Klein, J., Le Traon, Y., Octeau, D., McDaniel, P.: Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. In: ACM SIGPLAN Notices, vol. 49, no. 6, pp. 259\u2013269 (2014)","journal-title":"ACM SIGPLAN Notices"},{"key":"23_CR10","unstructured":"Reina, A., Fattori, A., Cavallaro, L.: A system call-centric analysis and stimulation technique to automatically reconstruct android malware behaviors. In: EuroSec, April 2013"},{"key":"23_CR11","unstructured":"Fuchs, A.P., Chaudhuri, A., Foster, J.S.: Scandroid: automated security certification of android (2009)"},{"key":"23_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1007\/978-3-642-30921-2_17","volume-title":"Trust and Trustworthy Computing","author":"C Gibler","year":"2012","unstructured":"Gibler, C., Crussell, J., Erickson, J., Chen, H.: AndroidLeaks: automatically detecting potential privacy leaks in android applications on a large scale. In: Katzenbeisser, S., Weippl, E., Camp, L.J., Volkamer, M., Reiter, M., Zhang, X. (eds.) Trust 2012. LNCS, vol. 7344, pp. 291\u2013307. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-30921-2_17"},{"key":"23_CR13","doi-asserted-by":"crossref","unstructured":"Li, L., Bartel, A., Bissyand\u00e9, T.F., Klein, J., Le Traon, Y., Arzt, S., Rasthofer, S., Bodden, E., Octeau, D., McDaniel, P.: IccTA: Detecting inter-component privacy leaks in android apps. In: 37th International Conference on Software Engineering, vol. 1, pp. 280\u2013291. IEEE Press (2015)","DOI":"10.1109\/ICSE.2015.48"},{"key":"23_CR14","doi-asserted-by":"crossref","unstructured":"Chakradeo, S., Reaves, B., Traynor, P., Enck, W.: Mast: triage for market-scale mobile malware analysis. In: The Sixth ACM Conference on Security and Privacy in Wireless and Mobile Networks, pp. 12\u201324. ACM (2013)","DOI":"10.1145\/2462096.2462100"},{"key":"23_CR15","doi-asserted-by":"crossref","unstructured":"Wu, D.-J., Mao, C.-H., Wei, T.-E., Lee, H.-M., Wu, K.-P.: Droidmat: android malware detection through manifest and API calls tracing. In: Information Security IEEE, pp. 62\u201369. IEEE (2012)","DOI":"10.1109\/AsiaJCIS.2012.18"},{"key":"23_CR16","doi-asserted-by":"crossref","unstructured":"Burguera, I., Zurutuza, U., Nadjm-Tehrani, S.: Crowdroid: behavior-based malware detection system for android. In: ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, pp. 15\u201326. ACM (2011)","DOI":"10.1145\/2046614.2046619"},{"key":"23_CR17","doi-asserted-by":"crossref","unstructured":"Peng, H., Gates, C., Sarma, B., Li, N., Qi, Y., Potharaju, R., Nita-Rotaru, C., Molloy, I.: Using probabilistic generative models for ranking risks of android apps. In: 2012 ACM Conference on Computer and Communications Security, pp. 241\u2013252. ACM (2012)","DOI":"10.1145\/2382196.2382224"},{"issue":"2","key":"23_CR18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2619091","volume":"32","author":"W Enck","year":"2014","unstructured":"Enck, W., Gilbert, P., Han, S., Tendulkar, V., Chun, B.-G., Cox, L.P., Jung, J., McDaniel, P., Sheth, A.N.: TaintDroid: an information-flow tracking system for realtime privacy monitoring on smartphones. ACM Trans. Comput. Syst. (TOCS) 32(2), 1\u201329 (2014)","journal-title":"ACM Trans. Comput. Syst. (TOCS)"},{"key":"23_CR19","first-page":"6","volume":"2016","author":"O Somarriba","year":"2016","unstructured":"Somarriba, O., Zurutuza, U., Uribeetxeberria, R., Delosi\u00e8res, L., Nadjm-Tehrani, S.: Detection and visualization of android malware behavior. J. Electr. Comput. Eng. 2016, 6 (2016)","journal-title":"J. Electr. Comput. Eng."},{"key":"23_CR20","doi-asserted-by":"crossref","unstructured":"Park, W., Lee, K.H., Cho, K.S., Ryu, W.: Analyzing and detecting method of android malware via disassembling and visualization. In: International Conference on Information and Communication Technology Convergence, pp. 817\u2013818. IEEE (2014)","DOI":"10.1109\/ICTC.2014.6983300"},{"key":"23_CR21","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"574","DOI":"10.1007\/978-3-319-47364-2_56","volume-title":"International Joint Conference SOCO\u201916-CISIS\u201916-ICEUTE\u201916","author":"A Gonz\u00e1lez","year":"2017","unstructured":"Gonz\u00e1lez, A., Herrero, \u00c1., Corchado, E.: Neural visualization of android malware families. In: Gra\u00f1a, M., L\u00f3pez-Guede, J.M., Etxaniz, O., Herrero, \u00c1., Quinti\u00e1n, H., Corchado, E. (eds.) ICEUTE\/SOCO\/CISIS -2016. AISC, vol. 527, pp. 574\u2013583. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-47364-2_56"},{"issue":"2","key":"23_CR22","first-page":"55","volume":"4","author":"S Sakamoto","year":"2014","unstructured":"Sakamoto, S., Okuda, K., Nakatsuka, R., Yamauchi, T.: DroidTrack: tracking and visualizing information diffusion for preventing information leakage on android. J. Internet Serv. Inf. Secur. 4(2), 55\u201369 (2014)","journal-title":"J. Internet Serv. Inf. Secur."},{"key":"23_CR23","doi-asserted-by":"crossref","unstructured":"Grace, M., Zhou, Y., Zhang, Q., Zou, S., Jiang, X.: Riskranker: scalable and accurate zero-day android malware detection. In: The 10th International Conference on Mobile Systems, Applications, and Services, pp. 281\u2013294. ACM (2012)","DOI":"10.1145\/2307636.2307663"},{"key":"23_CR24","unstructured":"Wagner, M., Fischer, F., Luh, R., Haberson, A., Rind, A., Keim, D.A., Aigner, W.: A survey of visualization systems for malware analysis (2015)"},{"key":"23_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-85933-8_1","volume-title":"Visualization for Computer Security","author":"G Conti","year":"2008","unstructured":"Conti, G., Dean, E., Sinda, M., Sangster, B.: Visual reverse engineering of binary and data files. In: Goodall, J.R., Conti, G., Ma, K.-L. (eds.) VizSec 2008. LNCS, vol. 5210, pp. 1\u201317. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-85933-8_1"},{"key":"23_CR26","doi-asserted-by":"crossref","unstructured":"Quist, D.A., Liebrock, L.M.: Visualizing compiled executables for malware analysis. In: International Workshop on Visualization for Cyber Security, pp. 27\u201332. IEEE (2009)","DOI":"10.1109\/VIZSEC.2009.5375539"},{"key":"23_CR27","doi-asserted-by":"crossref","unstructured":"Trinius, P., Holz, T., Gbel, J., Freiling, F.C.: Visual analysis of malware behavior using treemaps and thread graphs. In: International Workshop on Visualization for Cyber Security, pp. 33\u201338. IEEE (2009)","DOI":"10.1109\/VIZSEC.2009.5375540"},{"key":"23_CR28","doi-asserted-by":"crossref","unstructured":"Grgio, A.R.A., Santos, R.D.C.: Visualization techniques for malware behavior analysis. In: Proceedings of SPIE - The International Society for Optical Engineering, vol. 801905\u2013801905-9 (2011)","DOI":"10.1117\/12.883441"},{"issue":"10","key":"23_CR29","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1057\/ivs.2010.11","volume":"10","author":"D Quist","year":"2011","unstructured":"Quist, D., Liebrock, L.M.: Reversing compiled executables for malware analysis via visualization. Inf. Vis. 10(10), 117\u2013126 (2011)","journal-title":"Inf. Vis."},{"key":"23_CR30","doi-asserted-by":"crossref","unstructured":"Chan, L.Y., Chuan, L.L., Ismail, M., Zainal, N.: A static and dynamic visual debugger for malware analysis. In: Communications, pp. 765\u2013769. IEEE (2012)","DOI":"10.1109\/APCC.2012.6388211"},{"key":"23_CR31","doi-asserted-by":"crossref","unstructured":"Zhuo, W., Nadjin, Y.: MalwareVis: entity-based visualization of malware network traces. In: The Ninth International Symposium on Visualization for Cyber Security, pp. 41\u201347. ACM (2012)","DOI":"10.1145\/2379690.2379696"},{"key":"23_CR32","doi-asserted-by":"crossref","unstructured":"Donahue, J., Paturi, A., Mukkamala, S.: Visualization techniques for efficient malware detection. In: IEEE International Conference on Intelligence and Security Informatics, pp. 289\u2013291. IEEE (2013)","DOI":"10.1109\/ISI.2013.6578845"},{"key":"23_CR33","unstructured":"Yan, L.K., Yin, H.: DroidScope: seamlessly reconstructing the OS and Dalvik semantic views for dynamic android malware analysis. In: The 21st USENIX Conference on Security Symposium, p 29. USENIX (2013)"},{"key":"23_CR34","unstructured":"G DATA news. https:\/\/www.gdata-software.com\/news\/2017\/04\/29715-350-new-android-malware-apps-every-hour"},{"key":"23_CR35","unstructured":"Androguard. https:\/\/github.com\/androguard\/androguard\/"},{"key":"23_CR36","doi-asserted-by":"crossref","unstructured":"Chan, P.P.F., Hui, L.C.K., Yiu, S.-M.: Droidchecker: analyzing android applications for capability leak. In: The Fifth ACM Conference on Security and Privacy in Wireless and Mobile Networks, pp. 125\u2013136. ACM (2012)","DOI":"10.1145\/2185448.2185466"},{"key":"23_CR37","unstructured":"Android malware genome project. http:\/\/www.malgenomeproject.org\/"},{"key":"23_CR38","doi-asserted-by":"crossref","unstructured":"Wang, K., Zhang, Y., Liu, P.: Call me back!: attacks on system server and system apps in android through synchronous callback. In: The 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 92\u2013103. ACM (2016)","DOI":"10.1145\/2976749.2978342"},{"key":"23_CR39","unstructured":"The Drebin dataset. https:\/\/www.sec.cs.tu-bs.de\/~danarp\/drebin\/index.html"},{"key":"23_CR40","unstructured":"TROJAN. https:\/\/www.f-secure.com\/v-descs\/trojan_android_fakeinst.shtml"},{"key":"23_CR41","unstructured":"VirusTotal. https:\/\/www.virustotal.com\/"},{"key":"23_CR42","unstructured":"Umeng. http:\/\/www.umeng.com\/"},{"key":"23_CR43","unstructured":"Google maps android API. https:\/\/developers.google.com\/maps\/documentation\/android-api\/"},{"key":"23_CR44","unstructured":"AdMob. https:\/\/www.google.com\/admob\/"},{"key":"23_CR45","unstructured":"The life cycle of activity. https:\/\/developer.android.com\/guide\/components\/activi-ties.html#Lifecycle"},{"key":"23_CR46","unstructured":"The life cycle of service. https:\/\/developer.android.com\/guide\/components\/service-s.html#Lifecycle"},{"key":"23_CR47","doi-asserted-by":"crossref","unstructured":"Chner, T., Pretschner, A., Ochoa, M.: DAVAST: data-centric system level activity visualization. In: Eleventh Workshop on Visualization for Cyber Security, pp. 25\u201332. ACM (2014)","DOI":"10.1145\/2671491.2671499"},{"key":"23_CR48","unstructured":"Kim, J., Yoon, Y., Yi, K., Shin, J.: SCANDAL: Static Analyzer for Detecting Privacy Leaks in Android Applications. Mobile Secur. Technol. Los Alamitos (2012)"},{"key":"23_CR49","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1007\/978-3-319-45744-4_20","volume-title":"Computer Security \u2013 ESORICS 2016","author":"X Zhang","year":"2016","unstructured":"Zhang, X., Aafer, Y., Ying, K., Du, W.: Hey, you, get off of my image: detecting data residue in android images. In: Askoxylakis, I., Ioannidis, S., Katsikas, S., Meadows, C. (eds.) ESORICS 2016. LNCS, vol. 9878, pp. 401\u2013421. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-45744-4_20"},{"key":"23_CR50","doi-asserted-by":"crossref","unstructured":"Huang, H., Zheng, C., Zeng, J., Zhou, W., Zhu, S., Liu, P., Chari, S., Zhang, C.: Android malware development on public malware scanning platforms: a large-scale data-driven study. In: 2016 IEEE International Conference on Big Data (Big Data), pp. 1090\u20131099. IEEE (2016)","DOI":"10.1109\/BigData.2016.7840712"},{"key":"23_CR51","doi-asserted-by":"crossref","unstructured":"Cao, Y., Fratantonio, Y., Bianchi, A., Egele, M., Kruegel, C., Vigna, G., Chen, Y.: EdgeMiner: automatically detecting implicit control flow transitions through the android framework. In: NDSS. NDSS (2015)","DOI":"10.14722\/ndss.2015.23140"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-78813-5_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,3]],"date-time":"2025-07-03T15:11:07Z","timestamp":1751555467000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-78813-5_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319788128","9783319788135"],"references-count":51,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-78813-5_23","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"11 April 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Niagara Falls","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 October 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 October 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/securecomm.eai-conferences.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}