{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T17:23:48Z","timestamp":1778693028120,"version":"3.51.4"},"reference-count":43,"publisher":"MDPI AG","issue":"15","license":[{"start":{"date-parts":[[2022,8,2]],"date-time":"2022-08-02T00:00:00Z","timestamp":1659398400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Smartphones are an essential part of all aspects of our lives. Socially, politically, and commercially, there is almost complete reliance on smartphones as a communication tool, a source of information, and for entertainment. Rapid developments in the world of information and cyber security have necessitated close attention to the privacy and protection of smartphone data. Spyware detection systems have recently been developed as a promising and encouraging solution for smartphone users\u2019 privacy protection. The Android operating system is the most widely used worldwide, making it a significant target for many parties interested in targeting smartphone users\u2019 privacy. This paper introduces a novel dataset collected in a realistic environment, obtained through a novel data collection methodology based on a unified activity list. The data are divided into three main classes: the first class represents normal smartphone traffic; the second class represents traffic data for the spyware installation process; finally, the third class represents spyware operation traffic data. The random forest classification algorithm was adopted to validate this dataset and the proposed model. Two methodologies were adopted for data classification: binary-class and multi-class classification. Good results were achieved in terms of accuracy. The overall average accuracy was 79% for the binary-class classification, and 77% for the multi-class classification. In the multi-class approach, the detection accuracy for spyware systems (UMobix, TheWiSPY, MobileSPY, FlexiSPY, and mSPY) was 90%, 83.7%, 69.3%, 69.2%, and 73.4%, respectively; in binary-class classification, the detection accuracy for spyware systems (UMobix, TheWiSPY, MobileSPY, FlexiSPY, and mSPY) was 93.9%, 85.63%, 71%, 72.3%, and 75.96%; respectively.<\/jats:p>","DOI":"10.3390\/s22155765","type":"journal-article","created":{"date-parts":[[2022,8,3]],"date-time":"2022-08-03T00:15:26Z","timestamp":1659485726000},"page":"5765","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":21,"title":["Android Spyware Detection Using Machine Learning: A Novel Dataset"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5582-5390","authenticated-orcid":false,"given":"Majdi K.","family":"Qabalin","sequence":"first","affiliation":[{"name":"Department of Computer Science, Princess Sumaya University for Technology, Amman 11941, Jordan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muawya","family":"Naser","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Princess Sumaya University for Technology, Amman 11941, Jordan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8396-7441","authenticated-orcid":false,"given":"Mouhammd","family":"Alkasassbeh","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Princess Sumaya University for Technology, Amman 11941, Jordan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,8,2]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"157","DOI":"10.14445\/22312803\/IJCTT-V60P124","article-title":"Review on Spyware\u2014A Malware Detection Using Datamining","volume":"60","author":"Pushpa","year":"2018","journal-title":"Int. J. Comput. Trends Technol."},{"key":"ref_2","unstructured":"(2022, May 18). Statistica. Android Statistics. Available online: https:\/\/www.statista.com\/statistics\/273840\/global-market-share-of-tablet-operating-systems-since-2010\/."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1385","DOI":"10.22214\/ijraset.2019.5234","article-title":"Self Propogating Malware with Varying Signature","volume":"7","author":"Panda","year":"2019","journal-title":"Int. J. Res. Appl. Sci. Eng. Technol."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"2691","DOI":"10.30534\/ijeter\/2020\/76862020","article-title":"Analyzing Android Users Based on Google Play Store Using K-Prototype Algorithm","volume":"8","author":"Girsang","year":"2020","journal-title":"Int. J. Emerg. Trends Eng. Res."},{"key":"ref_5","unstructured":"(2022, May 22). Kaspersky Security Bulletin. Statistics. Kaspersky, Available online: https:\/\/go.kaspersky.com\/rs\/802-IJN-240\/images\/KSB_statistics_2021_eng.pdf."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Heinrich, A., Bittner, N., and Hollick, M. (2022, January 16\u201319). AirGuard-Protecting Android Users from Stalking Attacks by Apple Find My Devices. Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks, San Antonio, TX, USA.","DOI":"10.1145\/3507657.3528546"},{"key":"ref_7","unstructured":"(2022, May 23). Mobile Malware Evolution. Mobile Malware Kaspersky. Available online: https:\/\/securelist.com\/mobile-malware-evolution-2021\/105876\/."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Chan, S. (2021). Hidden but Deadly: Stalkerware Usage in Intimate Partner Stalking. Introduction to Cyber Forensic Psychology: Understanding the Mind of the Cyber Deviant Perpetrators, World Scientific Publishing.","DOI":"10.1142\/9789811232411_0002"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1111\/spsr.12441","article-title":"Parsing Pegasus: An Infrastructural Approach to the Relationship between Technology and Swiss Security Politics","volume":"27","author":"Leander","year":"2021","journal-title":"Swiss Political Sci. Rev."},{"key":"ref_10","unstructured":"Lu, S., Guo, D., Ren, S., Huang, J., Svyatkovskiy, A., Blanco, A., and Liu, S. (2021). Codexglue: A machine learning benchmark dataset for code understanding and generation. arXiv."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"e190211","DOI":"10.1148\/ryai.2020190211","article-title":"Construction of a machine learning dataset through collaboration: The RSNA 2019 brain CT hemorrhage challenge","volume":"2","author":"Flanders","year":"2020","journal-title":"Radiol. Artif. Intell."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"851","DOI":"10.1177\/1077801220923731","article-title":"Operating-System Design and Its Implications for Victims of Family Violence: The Comparative Threat of Smart Phone Spyware for Android Versus iPhone Users","volume":"27","author":"Harkin","year":"2020","journal-title":"Violence Women"},{"key":"ref_13","unstructured":"Hutchinson, S., and Karabiyik, U. (2019, January 15\u201316). Forensic analysis of spy applications in android devices. Proceedings of the Annual ADFSL Conference on Digital Forensics, Security and Law, Daytona Beach, FL, USA."},{"key":"ref_14","unstructured":"Dedola, P., Vorozhtsov, G., Nazarov, V.K.K., and Schuricht, A.S.K. (2022, May 24). It Threat Evolution in Q1 2022. Mobile Statistics. Securelist English Global Securelistcom. Available online: https:\/\/securelist.com\/it-threat-evolution-in-q1-2022-mobile-statistics\/106589\/."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Conti, M., Rigoni, G., and Toffalini, F. (2020, January 25\u201328). ASAINT: A spy App identification system based on network traffic. Proceedings of the ARES \u201920\u2014The 15th International Conference on Availability, Reliability and Security, Virtual.","DOI":"10.1145\/3407023.3407076"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1016\/j.jnca.2018.01.011","article-title":"A root privilege management scheme with revocable authorization for Android devices","volume":"107","author":"Tan","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Ali-Gombe, A., Ahmed, I., Richard, G.G., and Roussev, V. (2016, January 9\u201311). AspectDroid: Android app analysis system. Proceedings of the CODASPY 2016\u20146th ACM Conference on Data and Application Security and Privacy, New Orleans, LO, USA.","DOI":"10.1145\/2857705.2857739"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Saad, M.H., Serageldin, A., and Salama, G.I. (2015, January 15\u201317). Android spyware disease and medication. Proceedings of the 2015 2nd International Conference on Information Security and Cyber Forensics, InfoSec, Cape Town, South Africa.","DOI":"10.1109\/InfoSec.2015.7435516"},{"key":"ref_19","unstructured":"Carlsson, A., Pedersen, C., Persson, F., and Soderlund, G. (2018). KAUDroid: A Tool that Will Spy on Applications and How They Spy on Their Users, Karlstad University."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"465","DOI":"10.1016\/j.procs.2016.04.210","article-title":"An Android-based Trojan Spyware to Study the NotificationListener Service Vulnerability","volume":"83","author":"Abualola","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3382158","article-title":"A Data-Driven Characterization of Modern Android Spyware","volume":"11","author":"Pierazzi","year":"2020","journal-title":"ACM Trans. Manag. Inf. Syst."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"3511","DOI":"10.1109\/TIFS.2020.2975932","article-title":"Android Malware Detection via (Somewhat) Robust Irreversible Feature Transformations","volume":"15","author":"Han","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Wang, H., Si, J., Li, H., and Guo, Y. (2019, January 25\u201331). Rmvdroid: Towards a reliable android malware dataset with app metadata. Proceedings of the 2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR), Montreal, QC, Canada.","DOI":"10.1109\/MSR.2019.00067"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"794","DOI":"10.1016\/j.procs.2015.02.148","article-title":"Spyware Detection in Android Using Hybridization of Description Analysis, Permission Mapping and Interface Analysis","volume":"46","author":"Kaur","year":"2015","journal-title":"Procedia Comput. Sci."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Vanjire, S., and Lakshmi, M. (2021, January 24\u201326). Behavior-Based Malware Detection System Approach for Mobile Security Using Machine Learning. Proceedings of the 2021 International Conference on Artificial Intelligence and Machine Vision (AIMV), Gandhinagar, India.","DOI":"10.1109\/AIMV53313.2021.9671009"},{"key":"ref_26","unstructured":"Sutter, T., Lapagna, K., Berlich, P., Rennhard, M., and Germann, F. (2021). Web Content Signing with Service Workers. arXiv."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Malik, J., and Kaushal, R. (2016, January 5\u20138). CREDROID: Android malware detection by network traffic analysis. Proceedings of the PAMCO 2016\u20142nd MobiHoc International Workshop on Privacy-Aware Mobile Computing, Paderborn, Germany.","DOI":"10.1145\/2940343.2940348"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Arora, A., Garg, S., and Peddoju, S.K. (2014, January 10\u201312). Malware detection using network traffic analysis in android based mobile devices. Proceedings of the 8th International Conference on Next Generation Mobile Applications, Services and Technologies, NGMAST, Oxford, UK.","DOI":"10.1109\/NGMAST.2014.57"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1109\/TIFS.2017.2737970","article-title":"Robust Smartphone App Identification via Encrypted Network Traffic Analysis","volume":"13","author":"Taylor","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Gonzalez, H., Kadir, A.A., Stakhanova, N., Alzahrani, A.J., and Ghorbani, A.A. (2015, January 21\u201324). Exploring reverse engineering symptoms in Android apps. Proceedings of the Eighth European Workshop on System Security, Bordeaux, France.","DOI":"10.1145\/2751323.2751330"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Kosta, S., Perta, V.C., Stefa, J., Hui, P., and Mei, A. (2013, January 14\u201319). Clonedoc: Exploiting the cloud to leverage secure group collaboration mechanisms for smartphones. Proceedings of the 2013 IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Turin, Italy.","DOI":"10.1109\/INFCOMW.2013.6970704"},{"key":"ref_32","unstructured":"Yu, K.F. (2015). Monitor Network Traffic with Packet Capture (PCAP) on an Android Device, Army Research Lab Adelphi Md Computational and Information Sciences Directorate."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"555","DOI":"10.1108\/ICS-01-2020-0016","article-title":"A systematic literature review of the factors affecting smartphone user threat avoidance behavior","volume":"28","author":"Butler","year":"2020","journal-title":"Inf. Comput. Secur."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Goyette, N., Jodoin, P.M., Porikli, F., Konrad, J., and Ishwar, P. (2012, January 16\u201321). Changedetection. net: A new change detection benchmark dataset. Proceedings of the 2012 IEEE computer society conference on computer vision and pattern recognition workshops, Providence, RI, USA.","DOI":"10.1109\/CVPRW.2012.6238919"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Mesquita, F., Cannaviccio, M., Schmidek, J., Mirza, P., and Barbosa, D. (2019, January 3\u20137). Knowledgenet: A benchmark dataset for knowledge base population. Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP), Hong Kong, China.","DOI":"10.18653\/v1\/D19-1069"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1016\/j.isprsjprs.2016.01.011","article-title":"Random forest in remote sensing: A review of applications and future directions","volume":"114","author":"Belgiu","year":"2016","journal-title":"ISPRS J. Photogramm. Remote Sens."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"2913","DOI":"10.4304\/jcp.7.12.2913-2920","article-title":"An improved random forest classifier for text categorization","volume":"7","author":"Xu","year":"2012","journal-title":"J. Comput."},{"key":"ref_38","first-page":"215","article-title":"An improved random forest classifier for multi-class classification","volume":"3","author":"Chaudhary","year":"2016","journal-title":"Inf. Process. Agric."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1016\/j.jtbi.2016.02.020","article-title":"Predicting lysine phosphoglycerylation with fuzzy SVM by incorporating k-spaced amino acid pairs into Chou\u2019s general PseAAC","volume":"397","author":"Ju","year":"2016","journal-title":"J. Theor. Biol."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Trithipkaiwanpon, T., and Taetragool, U. (2021, January 19\u201322). Sensitivity Analysis of Random Forest Hyperparameters. Proceedings of the 18th International Conference on Electrical Engineering\/Electronics, Computer, Telecommunications and Information Technology (ECTI-CON), Chiang Mai, Thailand.","DOI":"10.1109\/ECTI-CON51831.2021.9454885"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1016\/j.ecolmodel.2017.01.024","article-title":"Should topographic metrics be considered when predicting species density of birds on a large geographical scale? A case of Random Forest approach","volume":"349","author":"Kosicki","year":"2017","journal-title":"Ecol. Model."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"19285","DOI":"10.1038\/s41598-021-98879-9","article-title":"A Random Forest approach to identify metrics that best predict match outcome and player ranking in the esport Rocket League","volume":"11","author":"Smithies","year":"2021","journal-title":"Sci. Rep."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"839","DOI":"10.14358\/PERS.78.8.839","article-title":"Mapping Fragmented Agricultural Systems in the Sudano-Sahelian Environments of Africa Using Random Forest and Ensemble Metrics of Coarse Resolution MODIS Imagery","volume":"78","author":"Vintrou","year":"2012","journal-title":"Photogramm. Eng. Remote Sens."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/15\/5765\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:01:28Z","timestamp":1760140888000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/15\/5765"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,2]]},"references-count":43,"journal-issue":{"issue":"15","published-online":{"date-parts":[[2022,8]]}},"alternative-id":["s22155765"],"URL":"https:\/\/doi.org\/10.3390\/s22155765","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,8,2]]}}}