{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,4]],"date-time":"2025-12-04T10:09:21Z","timestamp":1764842961550,"version":"build-2065373602"},"reference-count":58,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2024,11,26]],"date-time":"2024-11-26T00:00:00Z","timestamp":1732579200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["BDCC"],"abstract":"<jats:p>The Android operating system has become increasingly popular, not only on mobile phones but also in various other platforms such as Internet-of-Things devices, tablet computers, and wearable devices. Due to its open-source nature and significant market share, Android poses an attractive target for malicious actors. One of the notable security challenges associated with this operating system is riskware. Riskware refers to applications that may pose a security threat due to their vulnerability and potential for misuse. Although riskware constitutes a considerable portion of Android\u2019s ecosystem malware, it has not been studied as extensively as other types of malware such as ransomware and trojans. In this study, we employ machine learning techniques to analyze the behavior of different riskware families and identify similarities in their actions. Furthermore, our research identifies specific behaviors that can be used to distinguish these riskware families. To achieve these insights, we utilize various tools such as k-Means clustering, principal component analysis, extreme gradient boost classifiers, and Shapley additive explanation. Our findings can contribute significantly to the detection, identification, and forensic analysis of Android riskware.<\/jats:p>","DOI":"10.3390\/bdcc8120171","type":"journal-article","created":{"date-parts":[[2024,11,26]],"date-time":"2024-11-26T04:02:18Z","timestamp":1732593738000},"page":"171","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Behavioral Analysis of Android Riskware Families Using Clustering and Explainable Machine Learning"],"prefix":"10.3390","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4324-1774","authenticated-orcid":false,"given":"Mohammed M.","family":"Alani","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering and Computing Sciences, Rochester Institute of Technology (RIT-Dubai), Dubai P.O. Box 341055, United Arab Emirates"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8146-5843","authenticated-orcid":false,"given":"Moatsum","family":"Alawida","sequence":"additional","affiliation":[{"name":"Department of Computer Sciences, Abu Dhabi University, Abu Dhabi P.O. Box 59911, United Arab Emirates"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2024,11,26]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3417978","article-title":"A survey of android malware detection with deep neural models","volume":"53","author":"Qiu","year":"2020","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_2","unstructured":"(2023, December 26). Mobile OS Market Share Worldwide 2009\u20132023|Statista. Available online: https:\/\/www.statista.com\/statistics\/272698\/global-market-share-held-by-mobile-operating-systems-since-2009."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Khan, M.A., Ahmad, I., Nordin, A.N., Ahmed, A.E.S., Mewada, H., Daradkeh, Y.I., Rasheed, S., Eldin, E.T., and Shafiq, M. (2022). Smart android based home automation system using internet of things (IoT). Sustainability, 14.","DOI":"10.3390\/su141710717"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"S48","DOI":"10.1016\/j.diin.2018.01.007","article-title":"MalDozer: Automatic framework for android malware detection using deep learning","volume":"24","author":"Karbab","year":"2018","journal-title":"Digit. Investig."},{"key":"ref_5","first-page":"669","article-title":"A systematic literature review on the cyber security","volume":"9","author":"Perwej","year":"2021","journal-title":"Int. J. Sci. Res. Manag."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"130","DOI":"10.3991\/ijim.v11i3.6605","article-title":"Android Users Privacy Awareness Survey","volume":"11","author":"Alani","year":"2017","journal-title":"Int. J. Interact. Mob. Technol."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"62","DOI":"10.1016\/j.dss.2016.09.006","article-title":"Android application classification and anomaly detection with graph-based permission patterns","volume":"93","author":"Sokolova","year":"2017","journal-title":"Decis. Support Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"e4172","DOI":"10.1002\/cpe.4172","article-title":"Detection of malicious behavior in android apps through API calls and permission uses analysis","volume":"29","author":"Yang","year":"2017","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"2934","DOI":"10.1109\/TSE.2020.2975176","article-title":"A longitudinal study of application structure and behaviors in android","volume":"47","author":"Cai","year":"2020","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/TST.2016.7399288","article-title":"Droiddetector: Android malware characterization and detection using deep learning","volume":"21","author":"Yuan","year":"2016","journal-title":"Tsinghua Sci. Technol."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"102718","DOI":"10.1016\/j.cose.2022.102718","article-title":"AdStop: Efficient flow-based mobile adware detection using machine learning","volume":"117","author":"Alani","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1286","DOI":"10.1109\/TIFS.2017.2787905","article-title":"Uncovering the face of android ransomware: Characterization and real-time detection","volume":"13","author":"Chen","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Faruki, P., Bhan, R., Jain, V., Bhatia, S., El Madhoun, N., and Pamula, R. (2023). A Survey and Evaluation of Android-Based Malware Evasion Techniques and Detection Frameworks. Information, 14.","DOI":"10.3390\/info14070374"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Sk, H.K. (2022, January 29\u201331). A literature review on android mobile malware detection using machine learning techniques. Proceedings of the 2022 6th International Conference on Computing Methodologies and Communication (ICCMC), Erode, India.","DOI":"10.1109\/ICCMC53470.2022.9753746"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Kwon, H.Y., Kim, T., and Lee, M.K. (2022). Advanced intrusion detection combining signature-based and behavior-based detection methods. Electronics, 11.","DOI":"10.3390\/electronics11060867"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"73214","DOI":"10.1109\/ACCESS.2022.3189645","article-title":"Paired: An explainable lightweight android malware detection system","volume":"10","author":"Alani","year":"2022","journal-title":"IEEE Access"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"30996","DOI":"10.1109\/ACCESS.2018.2844349","article-title":"A novel dynamic android malware detection system with ensemble learning","volume":"6","author":"Feng","year":"2018","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Choudhary, M., and Kishore, B. (2018, January 4\u20136). Haamd: Hybrid analysis for android malware detection. Proceedings of the 2018 International Conference on Computer Communication and Informatics (ICCCI), Coimbatore, India.","DOI":"10.1109\/ICCCI.2018.8441295"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"100358","DOI":"10.1016\/j.cosrev.2020.100358","article-title":"A survey of malware detection in Android apps: Recommendations and perspectives for future research","volume":"39","author":"Razgallah","year":"2021","journal-title":"Comput. Sci. Rev."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"123314","DOI":"10.1109\/ACCESS.2023.3323396","article-title":"Protecting Android Devices from Malware Attacks: A State-of-the-Art Report of Concepts, Modern Learning Models and Challenges","volume":"11","author":"Bayazit","year":"2023","journal-title":"IEEE Access"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Jiang, C., Xia, C., Liu, Z., and Wang, T. (2023). FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems. Entropy, 25.","DOI":"10.3390\/e25071053"},{"key":"ref_22","unstructured":"Dimitrios, T. (2022). Privacy and Data Protection in Mobile Applications. [Master\u2019s Thesis, International Hellenic University]."},{"key":"ref_23","unstructured":"Jennings, A. (2023). Surveillance by Software: A Code for Employee Monitoring. [Ph.D. Thesis, ResearchSpace]."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"138","DOI":"10.1109\/MWC.2015.7054729","article-title":"Mobile application security: Malware threats and defenses","volume":"22","author":"He","year":"2015","journal-title":"IEEE Wirel. Commun."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"847","DOI":"10.22581\/muet1982.2104.14","article-title":"Detection and prevention of malware in android operating system","volume":"40","author":"Dahri","year":"2021","journal-title":"Mehran Univ. Res. J. Eng. Technol."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"491","DOI":"10.1504\/IJITST.2020.108142","article-title":"Android application security: Detecting Android malware and evaluating anti-malware software","volume":"10","author":"Rani","year":"2020","journal-title":"Int. J. Internet Technol. Secur. Trans."},{"key":"ref_27","first-page":"3506","article-title":"Android Malware Detection in Official and Third Party Application Stores","volume":"9","author":"Rani","year":"2018","journal-title":"Int. J. Adv. Netw. Appl."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1007\/s11416-012-0162-3","article-title":"Reducing the window of opportunity for Android malware Gotta catch\u2019em all","volume":"8","author":"Apvrille","year":"2012","journal-title":"J. Comput. Virol."},{"key":"ref_29","first-page":"463","article-title":"Android malware detection & protection: A survey","volume":"7","author":"Arshad","year":"2016","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"65579","DOI":"10.1109\/ACCESS.2019.2916648","article-title":"Unsupervised machine learning for networking: Techniques, applications and research challenges","volume":"7","author":"Usama","year":"2019","journal-title":"IEEE Access"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Ding, C., and He, X. (2004, January 4\u20138). K-means clustering via principal component analysis. Proceedings of the Twenty-First International Conference on Machine Learning, Banff, AB, Canada.","DOI":"10.1145\/1015330.1015408"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1002\/widm.53","article-title":"Algorithms for hierarchical clustering: An overview","volume":"2","author":"Murtagh","year":"2012","journal-title":"Wiley Interdiscip. Rev. Data Min. Knowl. Discov."},{"key":"ref_33","unstructured":"Bouman, C.A., Shapiro, M., Cook, G., Atkins, C.B., and Cheng, H. (1997). Cluster: An Unsupervised Algorithm for Modeling Gaussian Mixtures, The Board of Trustees of Purdue University."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"14575","DOI":"10.1109\/ACCESS.2022.3147951","article-title":"A novel mean-shift algorithm for data clustering","volume":"10","author":"Cariou","year":"2022","journal-title":"IEEE Access"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"42200","DOI":"10.1109\/ACCESS.2020.2976199","article-title":"Explainable Machine Learning for Scientific Insights and Discoveries","volume":"8","author":"Roscher","year":"2020","journal-title":"IEEE Access"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"52138","DOI":"10.1109\/ACCESS.2018.2870052","article-title":"Peeking Inside the Black-Box: A Survey on Explainable Artificial Intelligence (XAI)","volume":"6","author":"Adadi","year":"2018","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1016\/j.dss.2010.12.003","article-title":"An empirical evaluation of the comprehensibility of decision table, tree and rule based predictive models","volume":"51","author":"Huysmans","year":"2011","journal-title":"Decis. Support Syst."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"1350","DOI":"10.1214\/15-AOAS848","article-title":"Interpretable classifiers using rules and Bayesian analysis: Building a better stroke prediction model","volume":"9","author":"Letham","year":"2015","journal-title":"Ann. Appl. Stat."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., and Guestrin, C. (2016). \u201cWhy Should I Trust You?\u201d: Explaining the Predictions of Any Classifier. arXiv.","DOI":"10.18653\/v1\/N16-3020"},{"key":"ref_40","first-page":"3395","article-title":"Synthesizing the preferred inputs for neurons in neural networks via deep generator networks","volume":"29","author":"Nguyen","year":"2016","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_41","first-page":"4765","article-title":"A unified approach to interpreting model predictions","volume":"30","author":"Lundberg","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"647","DOI":"10.1007\/s10115-013-0679-x","article-title":"Explaining prediction models and individual predictions with feature contributions","volume":"41","author":"Kononenko","year":"2014","journal-title":"Knowl. Inf. Syst."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Kouliaridis, V., and Kambourakis, G. (2021). A comprehensive survey on machine learning techniques for android malware detection. Information, 12.","DOI":"10.3390\/info12050185"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1007\/s11416-015-0244-0","article-title":"Behavior-based features model for malware detection","volume":"12","author":"Galal","year":"2016","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"122255","DOI":"10.1016\/j.eswa.2023.122255","article-title":"Detection approaches for android malware: Taxonomy and review analysis","volume":"238","author":"Manzil","year":"2023","journal-title":"Expert Syst. Appl."},{"key":"ref_46","unstructured":"Felt, A.P., Greenwood, K., and Wagner, D. (2010). The Effectiveness of Install-Time Permission Systems for Third-Party Applications, University of California at Berkely. Technical Report for University of California at Berkely, Electrical Engineering and Computer Sciences."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"79","DOI":"10.4316\/AECE.2022.03009","article-title":"An Entropy-based Method for Social Apps Privacy Assessment Using the Android Permissions Architecture","volume":"22","author":"Sandor","year":"2022","journal-title":"Adv. Electr. Comput. Eng."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"110533","DOI":"10.1016\/j.jss.2020.110533","article-title":"An Android application risk evaluation framework based on minimum permission set identification","volume":"163","author":"Xiao","year":"2020","journal-title":"J. Syst. Softw."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Khullar, V., Gera, T., and Mehta, T. (2023, January 24\u201326). Static Method to Locate Risky Features in Android Applications. Proceedings of the 2023 2nd Edition of IEEE Delhi Section Flagship Conference (DELCON), Rajpura, India.","DOI":"10.1109\/DELCON57910.2023.10127577"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"103277","DOI":"10.1016\/j.cose.2023.103277","article-title":"A system call-based android malware detection approach with homogeneous & heterogeneous ensemble machine learning","volume":"130","author":"Bhat","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"103651","DOI":"10.1016\/j.cose.2023.103651","article-title":"A Novel Android Malware Detection Method with API Semantics Extraction","volume":"137","author":"Yang","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Liu, T., Zhang, H., Long, H., Shi, J., and Yao, Y. (2022). Convolution neural network with batch normalization and inception-residual modules for Android malware classification. Sci. Rep., 12.","DOI":"10.1038\/s41598-022-18402-6"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Mariconti, E., Onwuzurike, L., Andriotis, P., De Cristofaro, E., Ross, G., and Stringhini, G. (2016). Mamadroid: Detecting android malware by building markov chains of behavioral models. arXiv.","DOI":"10.14722\/ndss.2017.23353"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Rahali, A., Lashkari, A.H., Kaur, G., Taheri, L., Gagnon, F., and Massicotte, F. (2020, January 21\u201323). Didroid: Android malware classification and characterization using deep image learning. Proceedings of the 2020 The 10th International Conference on Communication and Network Security, Xi\u2019an, China.","DOI":"10.1145\/3442520.3442522"},{"key":"ref_55","unstructured":"(2023, December 26). AndMal 2020|Datasets|Research|Canadian Institute for Cybersecurity|UNB. Available online: https:\/\/www.unb.ca\/cic\/datasets\/andmal2020.html."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Gan, G., Ma, C., and Wu, J. (2020). Data Clustering: Theory, Algorithms, and Applications, SIAM.","DOI":"10.1137\/1.9781611976335"},{"key":"ref_57","unstructured":"Kaur, G., and Lashkari, A.H. (2023, December 28). Understanding Android Malware Families: Riskware\u2014Is It Worth It? (Article 4)\u2014IT World Canada. Available online: https:\/\/www.itworldcanada.com\/blog\/understanding-android-malware-families-riskware-is-it-worth-it-article-4\/446692."},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Sch\u00fctte, J., Fedler, R., and Titze, D. (2015, January 24\u201327). Condroid: Targeted dynamic analysis of android applications. Proceedings of the 2015 IEEE 29th International Conference on Advanced Information Networking and Applications, Gwangiu, Republic of Korea.","DOI":"10.1109\/AINA.2015.238"}],"container-title":["Big Data and Cognitive Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2504-2289\/8\/12\/171\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T16:39:30Z","timestamp":1760114370000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2504-2289\/8\/12\/171"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,26]]},"references-count":58,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2024,12]]}},"alternative-id":["bdcc8120171"],"URL":"https:\/\/doi.org\/10.3390\/bdcc8120171","relation":{},"ISSN":["2504-2289"],"issn-type":[{"type":"electronic","value":"2504-2289"}],"subject":[],"published":{"date-parts":[[2024,11,26]]}}}