{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T23:28:24Z","timestamp":1782170904797,"version":"3.54.5"},"reference-count":35,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2021,8,3]],"date-time":"2021-08-03T00:00:00Z","timestamp":1627948800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"the Key grant Project of The National Social Science Fund of China","award":["20&ZD293"],"award-info":[{"award-number":["20&ZD293"]}]},{"name":"the Innovation Environment Construction Special Project of Xinjiang Uygur Autonomous Region","award":["PT1811"],"award-info":[{"award-number":["PT1811"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>With the popularity of Android, malware detection and family classification have also become a research focus. Many excellent methods have been proposed by previous authors, but static and dynamic analyses inevitably require complex processes. A hybrid analysis method for detecting Android malware and classifying malware families is presented in this paper, and is partially optimized for multiple-feature data. For static analysis, we use permissions and intent as static features and use three feature selection methods to form a subset of three candidate features. Compared with various models, including k-nearest neighbors and random forest, random forest is the best, with a detection rate of 95.04%, while the chi-square test is the best feature selection method. After using feature selection to explore the critical static features contained in this dataset, we analyzed a subset of important features to gain more insight into the malware. In a dynamic analysis based on network traffic, unlike those that focus on a one-way flow of traffic and work on HTTP protocols and transport layer protocols, we focused on sessions and retained protocol layers. The Res7LSTM model is then used to further classify the malicious and partially benign samples detected in the static detection. The experimental results show that our approach can not only work with fewer static features and guarantee sufficient accuracy, but also improve the detection rate of Android malware family classification from 71.48% in previous work to 99% when cutting the traffic in terms of the sessions and protocols of all layers.<\/jats:p>","DOI":"10.3390\/e23081009","type":"journal-article","created":{"date-parts":[[2021,8,3]],"date-time":"2021-08-03T08:16:39Z","timestamp":1627978599000},"page":"1009","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":48,"title":["A Hybrid Analysis-Based Approach to Android Malware Family Classification"],"prefix":"10.3390","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6008-7863","authenticated-orcid":false,"given":"Chao","family":"Ding","sequence":"first","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830046, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nurbol","family":"Luktarhan","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830046, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bei","family":"Lu","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830046, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6477-7781","authenticated-orcid":false,"given":"Wenhui","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830046, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,8,3]]},"reference":[{"key":"ref_1","unstructured":"(2020, July 27). Ericsson Mobility Report June 2020. Ericsson Mobility Report. Available online: https:\/\/www.ericsson.com\/49da93\/assets\/local\/mobility-report\/documents\/2020\/june2020-ericsson-mobility-report.pdf."},{"key":"ref_2","unstructured":"(2021, April 05). Smartphone Market Share. Available online: https:\/\/www.idc.com\/promo\/smartphone-market-share\/os."},{"key":"ref_3","unstructured":"Symantec, I. (2012, March 15). Internet Security Threat Report 2019. Available online: https:\/\/docs.broadcom.com\/doc\/istr-24-executive-summary-en."},{"key":"ref_4","unstructured":"(2021, April 05). 2019 Android Malware Special Report by 360 Security Brain. Available online: https:\/\/blogs.360.cn\/post\/review_android_malware_of_2019.html."},{"key":"ref_5","unstructured":"(2021, April 05). 2019 Mobile Ad Supply Chain Safety Report. Available online: http:\/\/info.pixalate.com\/mobile-advertising-supply-chain-safety-report-2019."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Liu, X., and Liu, J. (2014, January 8\u201311). A Two-Layered Permission-Based Android Malware Detection Scheme. Proceedings of the 2014 2nd IEEE International Conference on Mobile Cloud Computing, Services, and Engineering, Oxford, UK.","DOI":"10.1109\/MobileCloud.2014.22"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Noorbehbahani, F., Rasouli, F., and Saberi, M. (2019, January 28\u201329). Analysis of machine learning techniques for ransomware detection. Proceedings of the 2019 16th International ISC (Iranian Society of Cryptology) Conference on Information Security and Cryptology (ISCISC), Mashhad, Iran.","DOI":"10.1109\/ISCISC48546.2019.8985139"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Blanc, W., Hashem, L.G., Elish, K.O., and Almohri, M.J.H. (2019, January 9\u201312). Identifying android malware families using android-oriented metrics. Proceedings of the 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA.","DOI":"10.1109\/BigData47090.2019.9005669"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"102264","DOI":"10.1016\/j.cose.2021.102264","article-title":"GDroid: Android malware detection and classification with graph convolutional network","volume":"106","author":"Gao","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Hemalatha, J., Roseline, S.A., Geetha, S., Kadry, S., and Dama\u0161evi\u010dius, R. (2021). An Efficient DenseNet-Based Deep Learning Model for Malware Detection. Entropy, 23.","DOI":"10.3390\/e23030344"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Nisa, M., Shah, J.H., Kanwal, S., Raza, M., Khan, M.A., Dama\u0161evi\u010dius, R., and Bla\u017eauskas, T. (2020). Hybrid Malware Classification Method Using Segmentation-Based Fractal Texture Analysis and Deep Convolution Neural Network Features. Appl. Sci., 10.","DOI":"10.3390\/app10144966"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Dama\u0161evi\u010dius, R., Ven\u010dkauskas, A., Toldinas, J., and Grigali\u016bnas, \u0160. (2021). Ensemble-Based Classification Using Neural Networks and Machine Learning Models for Windows PE Malware Detection. Electronics, 10.","DOI":"10.3390\/electronics10040485"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Zhao, S., Li, X., Xu, G., Zhang, L., and Feng, Z. (2014, January 24\u201326). Attack tree based android malware detection with hybrid analysis. Proceedings of the 2014 IEEE 13th International Conference on Trust, Security and Privacy in Computing and Communications, Beijing, China.","DOI":"10.1109\/TrustCom.2014.49"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"4321","DOI":"10.1109\/ACCESS.2018.2792941","article-title":"Samadroid: A novel 3-level hybrid malware detection model for android operating system","volume":"6","author":"Arshad","year":"2018","journal-title":"IEEE Access"},{"key":"ref_15","unstructured":"Fauskrud, J. (2019). Hybrid Analysis for Android Malware Family Classification in a Time-Aware Setting. [Master\u2019s Thesis, NTNU]."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Lashkari, A.H., Kadir, A.F.A., Taheri, L., and Ghorbani, A.A. (2018, January 22\u201325). Toward developing a systematic approach to generate benchmark android malware datasets and classification. Proceedings of the 2018 International Carnahan Conference on Security Technology (ICCST), Montreal, QC, Canada.","DOI":"10.1109\/CCST.2018.8585560"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Taheri, L., Kadir, A.F.A., and Lashkari, A.H. (2019, January 1\u20133). Extensible android malware detection and family classification using network-flows and api-calls. Proceedings of the 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India.","DOI":"10.1109\/CCST.2019.8888430"},{"key":"ref_18","first-page":"1157","article-title":"An introduction to variable and feature selection","volume":"3","author":"Guyon","year":"2003","journal-title":"J. Mach. Learn. Res."},{"key":"ref_19","unstructured":"X Developers (2020, July 20). Xgboost Python Package. XGBoost Developers. Available online: https:\/\/xgboost.readthedocs.io\/en\/latest\/python\/python_intro.html."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"125786","DOI":"10.1109\/ACCESS.2020.3008081","article-title":"A two-layer deep learning method for android malware detection using network traffic","volume":"8","author":"Feng","year":"2020","journal-title":"IEEE Access"},{"key":"ref_21","unstructured":"Winsniewski, R. (2016, July 27). Apktool: A Tool for Reverse Engineering Android apk Files. Available online: https:\/\/ibotpeaches.github.io\/Apktool\/."},{"key":"ref_22","first-page":"2825","article-title":"Scikit-learn: Machine learning in python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1109\/MNET.2012.6135854","article-title":"Issues and future directions in traffic classification","volume":"26","author":"Dainotti","year":"2012","journal-title":"IEEE Netw."},{"key":"ref_24","unstructured":"Wang, W., Zhu, M., Zeng, X., Ye, X., and Sheng, Y. (2017, January 11\u201313). Malware traffic classification using convolutional neural network for representation learning. Proceedings of the 2017 International Conference on Information Networking (ICOIN), Da Nang, Vietnam."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","article-title":"Deep packet: A novel approach for encrypted traffic classification using deep learning","volume":"24","author":"Lotfollahi","year":"2020","journal-title":"Soft Comput."},{"key":"ref_26","unstructured":"LeCun, Y. (1998, July 20). The Mnist Database of Handwritten Digits. Available online: http:\/\/yann.lecun.com\/exdb\/mnist\/."},{"key":"ref_27","first-page":"1929","article-title":"Dropout: A simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"He, K., and Sun, J. (2015, January 7\u201312). Convolutional neural networks at constrained time cost. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Boston, MA, USA.","DOI":"10.1109\/CVPR.2015.7299173"},{"key":"ref_29","unstructured":"Srivastava, R.K., Greff, K., and Schmidhuber, J. (2015). Highway networks. arXiv."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","article-title":"Long short-term memory","volume":"9","author":"Hochreiter","year":"1997","journal-title":"Neural Comput."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1109\/72.279181","article-title":"Learning long-term dependencies with gradient descent is difficult","volume":"5","author":"Bengio","year":"1994","journal-title":"IEEE Trans. Neural Netw."},{"key":"ref_33","unstructured":"Total, V. (2013, July 20). Virus Total. Available online: https:\/\/www.virustotal.com."},{"key":"ref_34","unstructured":"Powers, D.M.W. (2020). Evaluation: From precision, recall and f-measure to roc, informedness, markedness and correlation. arXiv."},{"key":"ref_35","unstructured":"(2015, October 14). API Android. Available online: http:\/\/developer.android.com\/reference\/packages.html."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/23\/8\/1009\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:39:52Z","timestamp":1760164792000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/23\/8\/1009"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,3]]},"references-count":35,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2021,8]]}},"alternative-id":["e23081009"],"URL":"https:\/\/doi.org\/10.3390\/e23081009","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,8,3]]}}}