{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T06:33:08Z","timestamp":1785738788341,"version":"3.56.0"},"reference-count":22,"publisher":"Emerald","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,5,15]]},"abstract":"<jats:sec>\n                  <jats:title>Purpose<\/jats:title>\n                  <jats:p>The openness of the Android operating system offers users convenience but also exposes them to a multitude of malicious applications. Consequently, analyzing applications before installation has become a crucial research area in mobile security. Static analysis, known for its accuracy and low cost, is a prominent method within this field. This paper aims to propose an ML\/DL-based approach to detect benign and malicious applications in APK format.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Design\/methodology\/approach<\/jats:title>\n                  <jats:p>The analysis method, detailed further in the paper, consists of five steps. Step 1, each APK file in the sample set undergoes decompilation to convert it into source code. Then, directed API call graph (DACG) generator is used to analyze the decompiled source code from Step 1 and extract API calls. After that, the authors apply the graph2vec method to convert the DACG data set into characteristic subgraphs. Next, saving the necessary features that each model needs to learn from the vector set. This helps reduce the vector dimensionality for each model type and reduces time and noise by eliminating unnecessary features. Finally, training and evaluating the ability to detect Android malware based on popular machine learning algorithms such as Random Forest, support vector machine, K-nearest neighbor, logistic regression and one of the most powerful machine learning algorithms currently available, gradient boosting regression.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Findings<\/jats:title>\n                  <jats:p>The authors come to the conclusion, feature graphs based on API call graphs are effective in detecting Android malware. Experimental results demonstrate the proposed method\u2019s superiority over existing detection methods on a data set of 7,000 samples, achieving TPR\u2009&amp;gt;\u200997%, FPR &amp;lt; 1% and AUC\u223c0.98. Following these steps, a final classification will determine the safety of the tested application, aiding users in avoiding malware installation.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Research limitations\/implications<\/jats:title>\n                  <jats:p>Although some limitations remain to be addressed, the DACG construction method holds significant potential for further exploration. Future research will focus on integrating dynamic analysis techniques to broaden the detectable and classifiable Android malware categories. In addition, the authors aim to adapt the methodology for broader applicability to other system types, including the widely used ELF systems in Linux.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Originality\/value<\/jats:title>\n                  <jats:p>In the study, the authors addressed the issue of generating graph-based feature for Android malware detection in a meaningful, practical and efficient way. The results can be used as a pattern for similar scenarios and applications.<\/jats:p>\n               <\/jats:sec>","DOI":"10.1108\/ijwis-03-2024-0095","type":"journal-article","created":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T03:08:49Z","timestamp":1742872129000},"page":"183-204","source":"Crossref","is-referenced-by-count":4,"title":["A static method for detecting android malware based on directed API call"],"prefix":"10.1108","volume":"21","author":[{"given":"Manh","family":"Vu Minh","sequence":"first","affiliation":[{"name":"Posts and Telecommunications Institute of Technology Faculty of Information Security, , Hanoi City,","place":["Vietnam"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huy-Trung","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Research Institute of Posts and Telecommunications, Posts and Telecommunications Institute of Technology , Hanoi,","place":["Vietnam"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"H. Viet","family":"Le","sequence":"additional","affiliation":[{"name":"People\u2019s Security Academy Faculty of Cyber Security and High-Tech Crime Prevention, , Hanoi City,","place":["Vietnam"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tri Duc","family":"Nguyen","sequence":"additional","affiliation":[{"name":"People\u2019s Security Academy Faculty of Cyber Security and High-Tech Crime Prevention, , Hanoi City,","place":["Vietnam"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuan Cho","family":"Do","sequence":"additional","affiliation":[{"name":"Posts and Telecommunications Institute of Technology Faculty of Information Security, , Hanoi City,","place":["Vietnam"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","published-online":{"date-parts":[[2025,3,27]]},"reference":[{"key":"2025081308470872500_ref001","first-page":"468","article-title":"Androzoo: collecting millions of android apps for the research community","author":"Allix","year":"2016"},{"key":"2025081308470872500_ref002","doi-asserted-by":"crossref","first-page":"101663","DOI":"10.1016\/j.cose.2019.101663","article-title":"DL-Droid: deep learning based android malware detection using real devices","volume":"89","author":"Alzaylaee","year":"2020","journal-title":"Computers and Security"},{"issue":"4","key":"2025081308470872500_ref003","doi-asserted-by":"crossref","first-page":"2789","DOI":"10.1007\/s10586-019-03045-6","article-title":"SysDroid: a dynamic ML-based android malware analyzer using system call traces","volume":"23","author":"Ananya","year":"2020","journal-title":"Cluster Computing"},{"key":"2025081308470872500_ref004","first-page":"81","article-title":"Dexray: a simple, yet effective deep learning approach to android malware detection based on image representation of bytecode","author":"Daoudi","year":"2021"},{"key":"2025081308470872500_ref005","doi-asserted-by":"crossref","first-page":"308","DOI":"10.1016\/j.cose.2017.03.008","article-title":"Security threats in Bluetooth technology","volume":"74","author":"Hassan","year":"2018","journal-title":"Computers and Security"},{"key":"2025081308470872500_ref006","article-title":"Android is the most popular mobile operating system","author":"Magas","year":"2018"},{"key":"2025081308470872500_ref007","article-title":"graph2vec: learning distributed representations of graphs","author":"Narayanan","year":"2017"},{"key":"2025081308470872500_ref008","first-page":"198","article-title":"An android malware detection method based on CNN mixed-data model","volume-title":"Presented at the ICTERI Workshops","author":"Nicheporuk","year":"2020"},{"issue":"2","key":"2025081308470872500_ref009","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3313391","article-title":"Mamadroid: detecting android malware by building Markov chains of behavioral models (extended version)","volume":"22","author":"Onwuzurike","year":"2019","journal-title":"ACM Transactions on Privacy and Security"},{"key":"2025081308470872500_ref010","first-page":"2825","article-title":"Scikit-learn: machine learning in python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res"},{"key":"2025081308470872500_ref011","doi-asserted-by":"crossref","first-page":"101792","DOI":"10.1016\/j.cose.2020.101792","article-title":"AMalNet: a deep learning framework based on graph convolutional networks for malware detection","volume":"93","author":"Pei","year":"2020","journal-title":"Computers and Security"},{"issue":"2","key":"2025081308470872500_ref012","doi-asserted-by":"crossref","first-page":"1027","DOI":"10.1007\/s00500-019-03940-5","article-title":"Deep learning for effective android malware detection using API call graph embeddings","volume":"24","author":"Pekta\u015f","year":"2020","journal-title":"Soft Computing"},{"key":"2025081308470872500_ref013","first-page":"12","article-title":"Automatic feature extraction, categorization and detection of malicious code in android applications","volume":"3","author":"Qadir","year":"2014","journal-title":"Int. J. Inf. Netw. Secur"},{"key":"2025081308470872500_ref014","first-page":"34","article-title":"De-LADY: deep learning based android malware detection using dynamic features","volume":"11","author":"Sihag","year":"2021","journal-title":"J Internet Serv Inf Secur"},{"key":"2025081308470872500_ref015","first-page":"153","article-title":"Decompiling and disassembling android applications","author":"Stevenson","year":"2021","journal-title":"Android Softw. Intern. Quick Ref. Field Man. Secur. Ref. Guide Java-Based Android Compon"},{"key":"2025081308470872500_ref016","doi-asserted-by":"crossref","first-page":"230","DOI":"10.1016\/j.future.2019.11.034","article-title":"Similarity-based android malware detection using Hamming distance of static binary features","volume":"105","author":"Taheri","year":"2020","journal-title":"Future Generation Computer Systems"},{"key":"2025081308470872500_ref017","first-page":"279","article-title":"Android malware detection using function call graph with graph convolutional networks","author":"Vinayaka","year":"2021"},{"key":"2025081308470872500_ref018","doi-asserted-by":"crossref","first-page":"25696","DOI":"10.1109\/ACCESS.2022.3155695","article-title":"A malware detection approach using autoencoder in deep learning","volume":"10","author":"Xing","year":"2022","journal-title":"IEEE Access"},{"issue":"2","key":"2025081308470872500_ref019","doi-asserted-by":"crossref","first-page":"186","DOI":"10.3390\/electronics10020186","article-title":"Android malware detection based on structural features of the function call graph","volume":"10","author":"Yang","year":"2021","journal-title":"Electronics"},{"key":"2025081308470872500_ref020","doi-asserted-by":"crossref","first-page":"107069","DOI":"10.1016\/j.asoc.2020.107069","article-title":"Deep learning feature exploration for android malware detection","volume":"102","author":"Zhang","year":"2021","journal-title":"Applied Soft Computing"},{"key":"2025081308470872500_ref021","first-page":"95","article-title":"Dissecting android malware: characterization and evolution\u201d. Presented at the","author":"Zhou","year":"2012"},{"key":"2025081308470872500_ref022","doi-asserted-by":"crossref","first-page":"118705","DOI":"10.1016\/j.eswa.2022.118705","article-title":"Android malware detection based on multi-head squeeze-and-excitation residual network","volume":"212","author":"Zhu","year":"2023","journal-title":"Expert Systems with Applications"}],"container-title":["International Journal of Web Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IJWIS-03-2024-0095\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/ijwis\/article-pdf\/21\/3\/183\/10063670\/ijwis-03-2024-0095.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/www.emerald.com\/ijwis\/article-pdf\/21\/3\/183\/10063670\/ijwis-03-2024-0095.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T12:47:15Z","timestamp":1755089235000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.emerald.com\/ijwis\/article\/21\/3\/183\/1273635\/A-static-method-for-detecting-android-malware"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,27]]},"references-count":22,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,5,15]]}},"URL":"https:\/\/doi.org\/10.1108\/ijwis-03-2024-0095","relation":{},"ISSN":["1744-0084","1744-0092"],"issn-type":[{"value":"1744-0084","type":"print"},{"value":"1744-0092","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,27]]}}}