{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T00:56:24Z","timestamp":1784595384546,"version":"3.55.0"},"reference-count":75,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2017,8,30]],"date-time":"2017-08-30T00:00:00Z","timestamp":1504051200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2018,6]]},"DOI":"10.1007\/s10664-017-9539-8","type":"journal-article","created":{"date-parts":[[2017,8,30]],"date-time":"2017-08-30T02:17:33Z","timestamp":1504059453000},"page":"1222-1274","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":83,"title":["A multi-view context-aware approach to Android malware detection and malicious code localization"],"prefix":"10.1007","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8452-3703","authenticated-orcid":false,"given":"Annamalai","family":"Narayanan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mahinthan","family":"Chandramohan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lihui","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,8,30]]},"reference":[{"key":"9539_CR1","doi-asserted-by":"crossref","unstructured":"Aafer Y et al (2013) DroidAPIMiner: Mining API-level features for robust malware detection in android. In: International conference on security and privacy in communication systems. Springer International Publishing","DOI":"10.1007\/978-3-319-04283-1_6"},{"key":"9539_CR2","unstructured":"Adagio source code. \n                    https:\/\/github.com\/hgascon\/adagio\n                    \n                   (accessed April 2017)"},{"key":"9539_CR3","volume-title":"Machine learning-based malware detection for android applications: history matters!","author":"K Allix","year":"2014","unstructured":"Allix K et al (2014) Machine learning-based malware detection for android applications: history matters! University of Luxembourg SnT, Luxembourg"},{"issue":"1","key":"9539_CR4","doi-asserted-by":"crossref","first-page":"183","DOI":"10.1007\/s10664-014-9352-6","volume":"21","author":"Kevin Allix","year":"2014","unstructured":"Allix K et al (2016a) Empirical assessment of machine learning-based malware detectors for Android. Empirical Softw Eng 21(1):183\u2013211","journal-title":"Empirical Software Engineering"},{"key":"9539_CR5","doi-asserted-by":"crossref","unstructured":"Allix K et al (2016b) Androzoo: Collecting millions of android apps for the research community. In: Proceedings of the 13th international conference on mining software repositories . ACM","DOI":"10.1145\/2901739.2903508"},{"key":"9539_CR6","unstructured":"Android Drawer third-party market. \n                    https:\/\/www.androiddrawer.com\n                    \n                   (accessed April 2017)"},{"key":"9539_CR7","unstructured":"Androguard. \n                    https:\/\/code.google.com\/p\/androguard\n                    \n                   (accessed April 2017)"},{"key":"9539_CR8","unstructured":"Anzhi third-party market. \n                    www.anzhi.com\n                    \n                   (accessed April 2017)"},{"key":"9539_CR9","unstructured":"AppsApk third-party market. \n                    http:\/\/www.appsapk.com\/\n                    \n                   (accessed April 2017)"},{"key":"9539_CR10","doi-asserted-by":"crossref","unstructured":"Arp D et al (2014) Drebin: Effective and explainable detection of android malware in your pocket. In: Proceedings of the annual symposium on network and distributed system security (NDSS)","DOI":"10.14722\/ndss.2014.23247"},{"issue":"6","key":"9539_CR11","doi-asserted-by":"crossref","first-page":"259","DOI":"10.1145\/2666356.2594299","volume":"49","author":"S Arzt","year":"2014","unstructured":"Arzt S et al (2014) Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. Acm Sigplan Not 49(6):259\u2013269","journal-title":"Acm Sigplan Not"},{"key":"9539_CR12","doi-asserted-by":"crossref","unstructured":"Au KWY et al (2012) Pscout: analyzing the android permission specification. In: Proceedings of the 2012 ACM conference on computer and communications security. ACM","DOI":"10.1145\/2382196.2382222"},{"key":"9539_CR13","doi-asserted-by":"crossref","unstructured":"Avdiienko V et al (2015) Mining apps for abnormal usage of sensitive data. In: 2015 IEEE\/ACM 37th IEEE international conference on software engineering (ICSE), vol 1. IEEE","DOI":"10.1109\/ICSE.2015.61"},{"key":"9539_CR14","doi-asserted-by":"crossref","unstructured":"Biggio B et al (2014) Poisoning behavioral malware clustering. In: Proceedings of the 2014 workshop on artificial intelligent and security workshop. ACM","DOI":"10.1145\/2666652.2666666"},{"key":"9539_CR15","unstructured":"Borgwardt KM, Kriegel H-P (2005) Shortest-path kernels on graphs. In: Fifth IEEE international conference on data mining (ICDM\u201905). IEEE"},{"issue":"2","key":"9539_CR16","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1023\/A:1009715923555","volume":"2","author":"CJC Burges","year":"1998","unstructured":"Burges CJC (1998) A tutorial on support vector machines for pattern recognition. Data Min Knowl Discov 2(2):121\u2013167","journal-title":"Data Min Knowl Discov"},{"key":"9539_CR17","doi-asserted-by":"crossref","unstructured":"Burguera I et al (2011) Crowdroid: behavior-based malware detection system for android. In: Proceedings of the 1st ACM workshop on security and privacy in smartphones and mobile devices. ACM","DOI":"10.1145\/2046614.2046619"},{"key":"9539_CR18","unstructured":"Cesare S, Xiang Y (2010) Classification of malware using structured control flow. In: Proceedings of the eighth Australasian aymposium on parallel and distributed computing, vol 107. Australian Computer Society, Inc., pp 61\u201370"},{"key":"9539_CR19","doi-asserted-by":"crossref","unstructured":"Chakradeo S et al (2013) Mast: triage for market-scale mobile malware analysis. In: Proceedings of the sixth ACM conference on security and privacy in wireless and mobile networks. ACM","DOI":"10.1145\/2462096.2462100"},{"key":"9539_CR20","unstructured":"Chen K et al (2015) Finding unknown malice in 10 seconds: Mass vetting for new threats at the google-play scale. In: 24th USENIX security symposium (USENIX Security 15)"},{"key":"9539_CR21","first-page":"1","volume":"7148","author":"SK Dash","year":"2016","unstructured":"Dash SK et al (2016) DroidScribe: Classifying android malware based on runtime behavior. Mob Secur Technol (MoST 2016) 7148:1\u201312","journal-title":"Mob Secur Technol (MoST 2016)"},{"key":"9539_CR22","doi-asserted-by":"crossref","unstructured":"Deo A et al (2016) Prescience: Probabilistic guidance on the retraining conundrum for malware detection. In: Proceedings of the 2016 ACM workshop on artificial intelligence and security. ACM","DOI":"10.1145\/2996758.2996769"},{"key":"9539_CR23","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1016\/j.cose.2014.11.001","volume":"49","author":"KO Elish","year":"2015","unstructured":"Elish KO et al (2015) Profiling user-trigger dependence for Android malware detection. Comput Secur 49:255\u2013273","journal-title":"Comput Secur"},{"key":"9539_CR24","unstructured":"Enrico M et al (2016) MAMADROID: Detecting android malware by building markov chains of behavioral models. arXiv:\n                    1612.04433"},{"key":"9539_CR25","unstructured":"FDroid third-party market. \n                    www.fdroid.org\n                    \n                   (accessed April 2017)"},{"key":"9539_CR26","doi-asserted-by":"crossref","unstructured":"Fredrikson M et al (2010) Synthesizing near-optimal malware specifications from suspicious behaviors. In: 2010 IEEE symposium on security and privacy (SP). IEEE","DOI":"10.1109\/SP.2010.11"},{"key":"9539_CR27","first-page":"1289","volume":"3","author":"G Forman","year":"2003","unstructured":"Forman G (2003) An extensive empirical study of feature selection metrics for text classification. J Mach Learn Res 3:1289\u20131305","journal-title":"J Mach Learn Res"},{"key":"9539_CR28","volume-title":"Obfuscation-resilient, efficient, and accurate detection and family identification of android malware","author":"J Garcia","year":"2015","unstructured":"Garcia J et al (2015) Obfuscation-resilient, efficient, and accurate detection and family identification of android malware. Department of Computer Science, George Mason University, Technical Report, USA"},{"key":"9539_CR29","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1007\/978-3-540-45167-9_11","volume-title":"On graph kernels: hardness results and efficient alternatives. Learning theory and kernel machines","author":"T G\u00e4rtner","year":"2003","unstructured":"G\u00e4rtner T et al (2003) On graph kernels: hardness results and efficient alternatives. Learning theory and kernel machines. Springer, Berlin Heidelberg, pp 129\u2013143"},{"key":"9539_CR30","unstructured":"Google Play. \n                    https:\/\/play.google.com\/store\n                    \n                   (accessed April 2017)"},{"key":"9539_CR31","first-page":"2211","volume":"12","author":"M G\u00f6nen","year":"2011","unstructured":"G\u00f6nen M, Alpayd\u0131n E (2011) Multiple kernel learning algorithms. J Mach Learn Res 12:2211\u20132268","journal-title":"J Mach Learn Res"},{"key":"9539_CR32","doi-asserted-by":"crossref","unstructured":"Gorla A et al (2014) Checking app behavior against app descriptions. In: Proceedings of the 36th international conference on software engineering. ACM","DOI":"10.1145\/2568225.2568276"},{"key":"9539_CR33","doi-asserted-by":"crossref","unstructured":"Gordon MI et al (2015) Information flow analysis of android applications in droidSafe. NDSS","DOI":"10.14722\/ndss.2015.23089"},{"key":"9539_CR34","doi-asserted-by":"crossref","unstructured":"Gascon H et al (2013) Structural detection of android malware using embedded call graphs. In: Proceedings of the 2013 ACM workshop on artificial intelligence and security. ACM","DOI":"10.1145\/2517312.2517315"},{"key":"9539_CR35","first-page":"1157","volume":"3","author":"I Guyon","year":"2003","unstructured":"Guyon I, Elisseeff A (2003) An introduction to variable and feature selection. J Mach Learn Res 3:1157\u20131182","journal-title":"J Mach Learn Res"},{"key":"9539_CR36","doi-asserted-by":"crossref","unstructured":"Hassen M, Chan PK (2017) Scalable Function Call Graph-based Malware Classification","DOI":"10.1145\/3029806.3029824"},{"key":"9539_CR37","doi-asserted-by":"crossref","unstructured":"Hido S, Kashima H (2009) A linear-time graph kernel. In: Ninth IEEE international conference on data mining 2009. ICDM\u201909. IEEE","DOI":"10.1109\/ICDM.2009.30"},{"issue":"2","key":"9539_CR38","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1007\/s10994-012-5319-2","volume":"90","author":"SCH Hoi","year":"2013","unstructured":"Hoi SCH et al (2013) Online multiple kernel classification. Mach Learn 90 (2):289\u2013316","journal-title":"Mach Learn"},{"key":"9539_CR39","doi-asserted-by":"crossref","unstructured":"Kantchelian A et al (2013) Approaches to adversarial drift. In: Proceedings of the 2013 ACM workshop on artificial intelligence and security. ACM","DOI":"10.1145\/2517312.2517320"},{"issue":"4","key":"9539_CR40","first-page":"76","volume":"49","author":"T Kimberly","year":"2017","unstructured":"Kimberly T et al (2017) The evolution of android malware and android analysis techniques. ACM Comput Surv (CSUR) 49(4):76","journal-title":"ACM Comput Surv (CSUR)"},{"key":"9539_CR41","unstructured":"Kriege NM et al (2017) A unifying view of explicit and implicit feature maps for structured data: systematic studies of graph kernels. arXiv:\n                    1703.00676"},{"key":"9539_CR42","unstructured":"Kaspersky 2016 Threat Report. \n                    https:\/\/kasperskycontenthub.com\/securelist\/files\/2016\/12\/Kaspersky_Security_Bulleti_2016_Review_ENG.eps\n                    \n                   (accessed April 2017)"},{"key":"9539_CR43","doi-asserted-by":"crossref","unstructured":"Li L et al (2015) Iccta: Detecting inter-component privacy leaks in android apps. In: Proceedings of the 37th international conference on software engineering, vol 1. IEEE Press","DOI":"10.1109\/ICSE.2015.48"},{"key":"9539_CR44","doi-asserted-by":"crossref","unstructured":"Li L et al (2017a) Understanding android app piggybacking: a systematic study of malicious code grafting. In: IEEE transactions on information forensics and security","DOI":"10.1109\/TIFS.2017.2656460"},{"key":"9539_CR45","doi-asserted-by":"crossref","unstructured":"Li L et al (2017b) Automatically locating malicious packages in piggybacked android apps. In: Proceedings of the international workshop on mobile software engineering and systems. ACM","DOI":"10.1109\/MOBILESoft.2017.6"},{"key":"9539_CR46","doi-asserted-by":"crossref","unstructured":"Ma J et al (2009) Identifying suspicious URLs: an application of large-scale online learning. In: Proceedings of the 26th annual international conference on machine learning. ACM","DOI":"10.1145\/1553374.1553462"},{"key":"9539_CR47","doi-asserted-by":"crossref","unstructured":"Meng G et al (2016) Mystique: evolving android malware for auditing anti-malware tools. In: Proceedings of the 11th ACM on Asia conference on computer and communications security. ACM","DOI":"10.1145\/2897845.2897856"},{"key":"9539_CR48","unstructured":"Mu Z et al (2014) Semantics-aware Android malware classification using weighted contextual API dependency graphs. In: Proceedings of the 2014 ACM SIGSAC conference on computer and communications security. ACM"},{"key":"9539_CR49","unstructured":"MKLDroid\u2019s website: \n                    https:\/\/sites.google.com\/view\/mkldroid\/home\n                    \n                   (accessed April 2017)"},{"key":"9539_CR50","unstructured":"Narayanan A et al (2016a) Subgraph2vec: learning distributed representations of rooted sub-graphs from large graphs. In: Workshop on mining and learning with graphs"},{"key":"9539_CR51","doi-asserted-by":"crossref","unstructured":"Narayanan A et al (2016b) Contextual weisfeiler-lehman graph kernel for malware detection. In: The 2016 international joint conference on neural networks (IJCNN). IEEE","DOI":"10.1109\/IJCNN.2016.7727817"},{"key":"9539_CR52","doi-asserted-by":"crossref","unstructured":"Narayanan A et al (2016c) Adaptive and scalable android malware detection through online learning. In: The 2016 international joint conference on neural networks (IJCNN). IEEE","DOI":"10.1109\/IJCNN.2016.7727508"},{"key":"9539_CR53","doi-asserted-by":"crossref","unstructured":"Octeau D et al (2015) Composite constant propagation: application to android inter-component communication analysis. In: Proceedings of the 37th international conference on software engineering, vol 1. IEEE Press","DOI":"10.1109\/ICSE.2015.30"},{"key":"9539_CR54","doi-asserted-by":"crossref","unstructured":"Peiravian N, Zhu X (2013) Machine learning for android malware detection using permission and api calls. In: 2013 IEEE 25th international conference on tools with artificial intelligence. IEEE","DOI":"10.1109\/ICTAI.2013.53"},{"key":"9539_CR55","unstructured":"Pouik et al (2012) Similarities for fun & profit. Phrack 14, 68. \n                    http:\/\/www.phrack.org\/issues.html?id=15&issue=68\n                    \n                   (accessed April 2017)"},{"key":"9539_CR56","doi-asserted-by":"crossref","unstructured":"Rasthofer S, Arzt S, Bodden E (2014) A machine-learning approach for classifying and categorizing android sources and sinks NDSS","DOI":"10.14722\/ndss.2014.23039"},{"key":"9539_CR57","doi-asserted-by":"crossref","unstructured":"Ribeiro MT et al (2016) Why Should I Trust You?: Explaining the predictions of any classifier. In: Proceedings of SIGKDD","DOI":"10.18653\/v1\/N16-3020"},{"key":"9539_CR58","doi-asserted-by":"crossref","unstructured":"Roy S et al (2015) Experimental study with real-world data for android app security analysis using machine learning. In: Proceedings of the 31st Annual Computer Security Applications Conference. ACM","DOI":"10.1145\/2818000.2818038"},{"key":"9539_CR59","doi-asserted-by":"crossref","unstructured":"Searles R et al (2017) Parallelization of machine learning applied to call graphs of binaries for malware detection. In: Proceedings of the 25th Euromicro International Conference on Parallel, Distributed and Network-Based Processing, PDP 2017, Russia","DOI":"10.1109\/PDP.2017.41"},{"key":"9539_CR60","doi-asserted-by":"crossref","unstructured":"Sahs J, Khan L (2012) A machine learning approach to android malware detection. In: 2012 European Intelligence and Security Informatics Conference (EISIC). IEEE","DOI":"10.1109\/EISIC.2012.34"},{"key":"9539_CR61","doi-asserted-by":"crossref","unstructured":"Singh A et al (2012) Tracking concept drift in malware families. In: Proceedings of the 5th ACM Workshop on Security and Artificial Intelligence. ACM","DOI":"10.1145\/2381896.2381910"},{"key":"9539_CR62","unstructured":"Saracino A et al (2016) Madam: Effective and efficient behavior-based android malware detection and prevention. In: IEEE Transactions on Dependable and Secure Computing"},{"key":"9539_CR63","unstructured":"Shervashidze N et al (2009) Efficient graphlet kernels for large graph comparison. AISTATS 5:488\u2013495"},{"key":"9539_CR64","first-page":"2539","volume":"12","author":"N Shervashidze","year":"2011","unstructured":"Shervashidze N et al (2011) Weisfeiler-lehman graph kernels. J Mach Learn Res 12:2539\u20132561","journal-title":"J Mach Learn Res"},{"key":"9539_CR65","unstructured":"SlideMe third-party market. \n                    www.SlideME.org\n                    \n                   (accessed April 2017)"},{"key":"9539_CR66","unstructured":"Soot framework. \n                    http:\/\/sable.github.io\/soot\n                    \n                   (accessed April 2017)"},{"key":"9539_CR67","doi-asserted-by":"crossref","unstructured":"Suarez-Tangil G et al (2016) DroidSieve: Fast and Accurate Classification of Obfuscated Android Malware","DOI":"10.1145\/3029806.3029825"},{"key":"9539_CR68","unstructured":"Sun Z, Ampornpunt N, Varma M, Vishwanathan S (2010) Multiple kernel learning and the SMO algorithm. In: Advances in Neural Information Processing Systems, pp 2361\u20132369"},{"key":"9539_CR69","doi-asserted-by":"crossref","unstructured":"Tian K e et al (2016) Analysis of code heterogeneity for high-precision classification of repackaged malware. In: 2016 IEEE Security and Privacy Workshops (SPW). IEEE","DOI":"10.1109\/SPW.2016.33"},{"key":"9539_CR70","unstructured":"Virus Share - malware collection. \n                    https:\/\/virusshare.com\n                    \n                   (accessed April 2017)"},{"key":"9539_CR71","doi-asserted-by":"crossref","unstructured":"Yanardag P, Vishwanathan S (2015) Deep graph kernels. In: Proceedings of SIGKDD","DOI":"10.1145\/2783258.2783417"},{"key":"9539_CR72","volume-title":"HADM: Hybrid analysis for detection of malware","author":"L Xu","year":"2016","unstructured":"Xu L et al (2016) HADM: Hybrid analysis for detection of malware. SAI Intelligent Systems Conference (IntelliSys), UK"},{"key":"9539_CR73","doi-asserted-by":"crossref","unstructured":"Yang C et al (2014) Droidminer: Automated mining and characterization of fine-grained malicious behaviors in android applications. In: Computer Security-ESORICS 2014. Springer International Publishing, pp 163\u2013182","DOI":"10.1007\/978-3-319-11203-9_10"},{"key":"9539_CR74","doi-asserted-by":"crossref","unstructured":"Yang W et al (2015) Appcontext: Differentiating malicious and benign mobile app behaviors using context. In: Proceedings of the International Conference on Software Engineering (ICSE)","DOI":"10.1109\/ICSE.2015.50"},{"key":"9539_CR75","doi-asserted-by":"crossref","unstructured":"Zhou Y, Jiang X (2012) Dissecting android malware: Characterization and evolution. In: 2012 IEEE Symposium on Security and Privacy (SP). IEEE","DOI":"10.1109\/SP.2012.16"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10664-017-9539-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-017-9539-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-017-9539-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,30]],"date-time":"2019-08-30T05:03:08Z","timestamp":1567141388000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10664-017-9539-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,30]]},"references-count":75,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2018,6]]}},"alternative-id":["9539"],"URL":"https:\/\/doi.org\/10.1007\/s10664-017-9539-8","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,8,30]]},"assertion":[{"value":"30 August 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}