{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T20:12:35Z","timestamp":1783714355024,"version":"3.55.0"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,3,9]],"date-time":"2023-03-09T00:00:00Z","timestamp":1678320000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,3,9]],"date-time":"2023-03-09T00:00:00Z","timestamp":1678320000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Malware attacks on the Android platform are rapidly increasing due to the high consumer adoption of Android smartphones. Advanced technologies have motivated cyber-criminals to actively create and disseminate a wide range of malware on Android smartphones. The researchers have conducted numerous studies on the detection of Android malware, but the majority of the works are based on the detection of generic Android malware. The detection based on malware categories will provide more insights about the malicious patterns of the malware. Therefore, this paper presents a detection solution for different Android malware categories, including adware, banking, SMS malware, and riskware. In this paper, a novel Huffman encoding-based feature vector generation technique is proposed. The experiments have proved that this novel approach significantly improves the efficiency of the detection model. This method makes use of system call frequencies as features to extract malware\u2019s dynamic behavior patterns. The proposed model was evaluated using machine learning and deep learning methods. The results show that the proposed model with the Random Forest classifier outperforms some existing methodologies with a detection accuracy of 98.70%.\n<\/jats:p>","DOI":"10.1186\/s42400-023-00139-y","type":"journal-article","created":{"date-parts":[[2023,3,9]],"date-time":"2023-03-09T00:02:34Z","timestamp":1678320154000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":54,"title":["Android malware category detection using a novel feature vector-based machine learning model"],"prefix":"10.1186","volume":"6","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2865-2794","authenticated-orcid":false,"given":"Hashida Haidros Rahima","family":"Manzil","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1059-8945","authenticated-orcid":false,"given":"S.","family":"Manohar Naik","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,3,9]]},"reference":[{"key":"139_CR1","doi-asserted-by":"crossref","unstructured":"Abderrahmane A, Adnane G, Yacine C, Khireddine G, (2019). Android malware detection based on system calls analysis and CNN classification. In: 2019 IEEE wireless communications and networking conference workshop (WCNCW)\u00a0(pp 1\u20136). IEEE","DOI":"10.1109\/WCNCW.2019.8902627"},{"key":"139_CR2","doi-asserted-by":"publisher","first-page":"841","DOI":"10.1016\/j.procs.2021.03.105","volume":"184","author":"M Almahmoud","year":"2021","unstructured":"Almahmoud M, Alzubi D, Yaseen Q (2021) ReDroidDet: android malware detection based on recurrent neural network. Procedia Comput Sci 184:841\u2013846. https:\/\/doi.org\/10.1016\/j.procs.2021.03.105","journal-title":"Procedia Comput Sci"},{"key":"139_CR3","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2883975","author":"F Alswaina","year":"2018","unstructured":"Alswaina F, Elleithy K (2018) Android malware permission-based multi-class classification using extremely randomized trees. IEEE Access. https:\/\/doi.org\/10.1109\/ACCESS.2018.2883975","journal-title":"IEEE Access"},{"issue":"6","key":"139_CR4","doi-asserted-by":"publisher","first-page":"942","DOI":"10.3390\/electronics9060942","volume":"9","author":"F Alswaina","year":"2020","unstructured":"Alswaina F, Elleithy K (2020) Android malware family classification and analysis: current status and future directions. Electronics 9(6):942","journal-title":"Electronics"},{"key":"139_CR5","first-page":"117","volume":"4","author":"A Ambarwari","year":"2020","unstructured":"Ambarwari A, Adrian QJ, Herdiyeni Y (2020) Analysis of the effect of data scaling on the performance of the machine learning algorithm for plant identification. J Resti Rekayasa Sist Dan Teknol Inf 4:117\u2013122","journal-title":"J Resti Rekayasa Sist Dan Teknol Inf"},{"key":"139_CR6","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2874502","author":"A Atzeni","year":"2018","unstructured":"Atzeni A, Diaz F, Marcelli A, S\u00e1nchez A, Squillero G, Tonda A (2018) Countering android malware: a scalable semi-supervised approach for family-signature generation. IEEE Access. https:\/\/doi.org\/10.1109\/ACCESS.2018.2874502","journal-title":"IEEE Access"},{"key":"139_CR7","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2020.107639","volume":"184","author":"Y Bai","year":"2021","unstructured":"Bai Y, Xing Z, Ma D, Li X, Feng Z (2021) Comparative analysis of feature representations and machine learning methods in android family classification. Comput Netw 184:107639","journal-title":"Comput Netw"},{"key":"139_CR8","unstructured":"Business of Apps: Android Statistics (2022). Android Statistics (2022) - Business of Apps Accessed on 20 July 2022"},{"key":"139_CR9","unstructured":"Canadian Institute for Cybersecurity, CICMalDroid 2020, https:\/\/www.unb.ca\/cic\/datasets\/maldroid-2020.html, Accessed on 30 Mar 2022"},{"key":"139_CR29","unstructured":"Contagio Mobile http:\/\/contagiominidump.blogspot.com\/, Accessed on 30 Mar 2022"},{"key":"139_CR11","unstructured":"CuckooDroid (2020). Cuckoodroid book. Retrieved 2020, from https:\/\/cuckoo-droid.readthedocs.io\/en\/latest\/"},{"issue":"3","key":"139_CR12","doi-asserted-by":"publisher","first-page":"786","DOI":"10.1080\/09540091.2021.1889977","volume":"33","author":"G D'Angelo","year":"2021","unstructured":"D\u2019Angelo G, Palmieri F, Robustelli A, Castiglione A (2021) Effective classification of android malware families through dynamic features and neural networks. Connect Sci 33(3):786\u2013801. https:\/\/doi.org\/10.1080\/09540091.2021.1889977","journal-title":"Connect Sci"},{"key":"139_CR13","doi-asserted-by":"publisher","DOI":"10.9781\/ijimai.2020.09.001","author":"M Dhalaria","year":"2021","unstructured":"Dhalaria M, Gandotra E (2021) A hybrid approach for android malware detection and family classification. Int J Interact Multimed Artif Intel. https:\/\/doi.org\/10.9781\/ijimai.2020.09.001","journal-title":"Int J Interact Multimed Artif Intel"},{"key":"139_CR14","doi-asserted-by":"publisher","first-page":"1009","DOI":"10.3390\/e23081009","volume":"23","author":"C Ding","year":"2021","unstructured":"Ding C, Luktarhan N, Lu B, Zhang W (2021) A hybrid analysis based approach to android malware family classification. Entropy 23:1009. https:\/\/doi.org\/10.3390\/e23081009","journal-title":"Entropy"},{"key":"139_CR15","doi-asserted-by":"publisher","first-page":"847","DOI":"10.1016\/j.procs.2021.03.106","volume":"184","author":"ON Elayan","year":"2021","unstructured":"Elayan ON, Mustafa AM (2021) Android malware detection using deep learning. Procedia Comput Sci 184:847\u2013852. https:\/\/doi.org\/10.1016\/j.procs.2021.03.106","journal-title":"Procedia Comput Sci"},{"key":"139_CR16","doi-asserted-by":"crossref","unstructured":"Fiky AHE, Shenawy AE, Madkour MA (2021) Android malware category and family detection and identification using machine learning. arXiv preprint https:\/\/arxiv.org\/abs\/2107.01927","DOI":"10.1109\/MIUCC52538.2021.9447661"},{"issue":"9","key":"139_CR17","first-page":"1098","volume":"40","author":"DA Huffman","year":"1952","unstructured":"Huffman DA (1952) A method for the construction of minimum-redundancy codes. Proc Inst Radio Eng 40(9):1098\u20131101","journal-title":"Proc Inst Radio Eng"},{"key":"139_CR18","unstructured":"Huffman coding, https:\/\/en.wikipedia.org\/wiki\/Huffman_coding, Accessed on 30 Mar 2022"},{"key":"139_CR19","doi-asserted-by":"publisher","first-page":"844","DOI":"10.1016\/j.future.2020.10.008","volume":"115","author":"SI Imtiaz","year":"2021","unstructured":"Imtiaz SI, Rehman SU, Javed AR, Jalil Z, Liu X, Alnumay WS (2021) DeepAMD: detection and identification of android malware using high-efficient deep artificial neural network. Future Gener Comput Syst 115:844\u2013856. https:\/\/doi.org\/10.1016\/j.future.2020.10.008","journal-title":"Future Gener Comput Syst"},{"key":"139_CR20","unstructured":"International Conference on Smart Sustainable Intelligent Computing and Applications under ICITETM2020 Android Malware Detection based on Vulnerable Feature Aggregation Arindaam Roya,_, Divjeet Singh Jasa, Gitanjali Jaggia, Kapil Sharmaa"},{"key":"139_CR21","doi-asserted-by":"publisher","first-page":"S48","DOI":"10.1016\/j.diin.2018.01.007","volume":"24","author":"E Karbab","year":"2018","unstructured":"Karbab E, Debbabi M, Derhab A, Mouheb D (2018) MalDozer: automatic framework for android malware detection using deep learning. Digit Investig 24:S48\u2013S59. https:\/\/doi.org\/10.1016\/j.diin.2018.01.007","journal-title":"Digit Investig"},{"key":"139_CR22","doi-asserted-by":"publisher","first-page":"10244","DOI":"10.3390\/app112110244","volume":"11","author":"M Kim","year":"2021","unstructured":"Kim M, Kim D, Hwang C, Cho S, Han S, Park M (2021) Machine-learning-based android malware family classification using built-in and custom permissions. Appl Sci 11:10244. https:\/\/doi.org\/10.3390\/app112110244","journal-title":"Appl Sci"},{"key":"139_CR23","unstructured":"Lee DH (2013) Pseudo-label: the simple and efficient semi-supervised learning method for deep neural networks. Workshop on challenges in representation learning, ICML. 3(2)"},{"issue":"1","key":"139_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10922-021-09634-4","volume":"30","author":"S Mahdavifar","year":"2022","unstructured":"Mahdavifar S, Alhadidi D, Ghorbani AA (2022) Effective and efficient hybrid android malware classification using pseudo-label stacked auto-encoder. J Netw Syst Manage 30(1):1\u201334","journal-title":"J Netw Syst Manage"},{"key":"139_CR25","doi-asserted-by":"publisher","first-page":"5183","DOI":"10.1007\/s00521-020-05309-4","volume":"33","author":"A Mahindru","year":"2021","unstructured":"Mahindru A, Sangal AL (2021a) MLDroid\u2014framework for Android malware detection using machine learning techniques. Neural Comput Appl 33:5183\u20135240. https:\/\/doi.org\/10.1007\/s00521-020-05309-4","journal-title":"Neural Comput Appl"},{"key":"139_CR26","doi-asserted-by":"publisher","first-page":"1369","DOI":"10.1007\/s13042-020-01238-9","volume":"12","author":"A Mahindru","year":"2021","unstructured":"Mahindru A, Sangal AL (2021b) SemiDroid: a behavioral malware detector based on unsupervised machine learning techniques using feature selection approaches. Int J Mach Learn Cyber 12:1369\u20131411. https:\/\/doi.org\/10.1007\/s13042-020-01238-9","journal-title":"Int J Mach Learn Cyber"},{"key":"139_CR10","doi-asserted-by":"crossref","unstructured":"Mahdavifar S, Kadir AFA, Fatemi R, Alhadidi D, Ghorbani AA (2020) Dynamic android malware category classification using semi-supervised deep learning, In: The 18th IEEE international conference on dependable, autonomic, and secure computing (DASC), 17\u201324","DOI":"10.1109\/DASC-PICom-CBDCom-CyberSciTech49142.2020.00094"},{"key":"139_CR27","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1016\/j.engappai.2018.06.006","volume":"74","author":"A Mart\u00edn","year":"2018","unstructured":"Mart\u00edn A, Rodr\u00edguez-Fern\u00e1ndez V, Camacho D (2018) CANDYMAN: classifying android malware families by modelling dynamic traces with Markov chains. Eng Appl Artif Intell 74:121\u2013133. https:\/\/doi.org\/10.1016\/j.engappai.2018.06.006","journal-title":"Eng Appl Artif Intell"},{"issue":"1","key":"139_CR28","doi-asserted-by":"publisher","first-page":"2007327","DOI":"10.1080\/08839514.2021.2007327","volume":"36","author":"L Meijin","year":"2022","unstructured":"Meijin L, Zhiyang F, Junfeng W, Luyu C, Qi Z, Tao Y, Yinwei W, Jiaxuan G (2022) A systematic overview of android malware detection. Appl Artif Intel 36(1):2007327. https:\/\/doi.org\/10.1080\/08839514.2021.2007327","journal-title":"Appl Artif Intel"},{"issue":"4","key":"139_CR30","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3342555","volume":"52","author":"A Moffat","year":"2019","unstructured":"Moffat A (2019) Huffman coding. ACM Comput Surv (CSUR) 52(4):1\u201335","journal-title":"ACM Comput Surv (CSUR)"},{"key":"139_CR31","unstructured":"Nicheporuk A, Savenko O, Nicheporuk A, Nicheporuk Y (2020) An android malware detection method based on CNN mixed-data model CEUR Workshop Proceedings Kharkiv, Ukraine. 2732:198\u2013213"},{"key":"139_CR32","doi-asserted-by":"publisher","unstructured":"Oyama Y, Giang TTD, Chubachi Y, Shinagawa T, Kato K (2012) Detecting malware signatures in a thin hypervisor, In: Proceedings of the 27th Annual ACM symposium on applied computing, SAC 12,\u00a0ACM,\u00a0New York, NY, USA, pp\u00a01807\u20131814,\u00a0https:\/\/doi.org\/10.1145\/2245276.2232070","DOI":"10.1145\/2245276.2232070"},{"key":"139_CR33","doi-asserted-by":"publisher","first-page":"101792","DOI":"10.1016\/j.cose.2020.101792","volume":"93","author":"X Pei","year":"2020","unstructured":"Pei X, Long Y, Tian S (2020) AMalNet: a deep learning framework based on graph convolutional networks for malware detection. Comput Secur 93:101792. https:\/\/doi.org\/10.1016\/j.cose.2020.101792","journal-title":"Comput Secur"},{"key":"139_CR34","doi-asserted-by":"publisher","unstructured":"Portokalidis G, Slowinska A, Bos Argos H (2006) An emulator for fingerprinting zero-day attacks for advertised honeypots with automatic signature generation, In: Proceedings of the 1st ACM SIGOPS\/EuroSys European Conference on Computer Systems 2006, EuroSys \u201906,\u00a0ACM,\u00a0New York, NY, USA, pp\u00a015\u201327,\u00a0https:\/\/doi.org\/10.1145\/1217935.1217938","DOI":"10.1145\/1217935.1217938"},{"key":"139_CR35","doi-asserted-by":"publisher","first-page":"985","DOI":"10.1093\/bib\/bbx153","volume":"20","author":"L Shahriyari","year":"2019","unstructured":"Shahriyari L (2019) Effect of normalization methods on the performance of supervised learning algorithms applied to HTSeq-FPKM- UQ data sets: 7SK RNA expression as a predictor of survival in patients with colon adenocarcinoma. Briefings Bioinform 20:985\u2013994","journal-title":"Briefings Bioinform"},{"key":"139_CR36","doi-asserted-by":"crossref","unstructured":"Shao K, Xiong Q, Cai Z (2021) FB2Droid: a novel malware family-based bagging algorithm for android malware detection. Secur Commun Netw","DOI":"10.1155\/2021\/6642252"},{"key":"139_CR37","unstructured":"Statista: Share of Android OS of global smartphone shipments from 1st quarter 2011 to 2nd quarter 2018* (2022) Android global phone market share 2018 | Statista Accessed on 21 July 2022"},{"key":"139_CR38","doi-asserted-by":"crossref","unstructured":"Taheri L, Kadir AFA, Lashkari AH (2019) Extensible android malware detection and family classification using network-flows and API-calls. In: 2019 International carnahan conference on security technology (ICCST) (pp 1\u20138). IEEE","DOI":"10.1109\/CCST.2019.8888430"},{"key":"139_CR39","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1007\/s42044-020-00068-w","volume":"4","author":"F Tchakount\u00e9","year":"2021","unstructured":"Tchakount\u00e9 F, Ngassi RCN, Kamla VC et al (2021) LimonDroid: a system coupling three signature-based schemes for profiling Android malware. Iran J Comput Sci 4:95\u2013114. https:\/\/doi.org\/10.1007\/s42044-020-00068-w","journal-title":"Iran J Comput Sci"},{"key":"139_CR40","unstructured":"Virus Total (2022) https:\/\/www.virustotal.com\/gui\/home\/upload, Accessed on 30 Mar 2022"},{"key":"139_CR41","doi-asserted-by":"publisher","unstructured":"Wressnegger C, Freeman K, Yamaguchi F, Rieck K (2017) Automatically inferring malware signatures for anti-virus assisted attacks. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS \u201917,\u00a0ACM,\u00a0New York, NY, USA, pp\u00a0587\u2013598,\u00a0https:\/\/doi.org\/10.1145\/3052973.3053002","DOI":"10.1145\/3052973.3053002"},{"key":"139_CR42","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1016\/j.cose.2018.10.001","volume":"80","author":"L Zhang","year":"2019","unstructured":"Zhang L, Thing VL, Cheng Y (2019) A scalable and extensible framework for android malware detection and family attribution. Comput Secur 80:120\u2013133","journal-title":"Comput Secur"},{"key":"139_CR43","doi-asserted-by":"publisher","first-page":"148404","DOI":"10.1109\/ACCESS.2020.3007571","volume":"8","author":"H Zhou","year":"2020","unstructured":"Zhou H, Yang X, Pan H, Guo W (2020) An android malware detection approach based on SIMGRU. IEEE Access 8:148404\u2013148410. https:\/\/doi.org\/10.1109\/ACCESS.2020.3007571","journal-title":"IEEE Access"},{"issue":"2","key":"139_CR44","doi-asserted-by":"publisher","first-page":"984","DOI":"10.1109\/TNSE.2020.2996379","volume":"8","author":"H Zhu","year":"2021","unstructured":"Zhu H, Li Y, Li R, Li J, You Z, Song H (2021) SEDMDroid: an enhanced stacking ensemble framework for android malware detection. IEEE Trans Netw Sci Eng 8(2):984\u2013994. https:\/\/doi.org\/10.1109\/TNSE.2020.2996379","journal-title":"IEEE Trans Netw Sci Eng"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00139-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-023-00139-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00139-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,3,9]],"date-time":"2023-03-09T00:03:41Z","timestamp":1678320221000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-023-00139-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,9]]},"references-count":44,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["139"],"URL":"https:\/\/doi.org\/10.1186\/s42400-023-00139-y","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,9]]},"assertion":[{"value":"24 August 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 January 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 March 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"6"}}