Behavioral Analysis of Android Riskware Families Using Clustering and Explainable Machine Learning
| dc.contributor.author | Alani, Mohammed M. | |
| dc.contributor.author | Alawida, Moatsum | |
| dc.date.accessioned | 2025-09-15T10:34:34Z | |
| dc.date.available | 2025-09-15T10:34:34Z | |
| dc.date.issued | 2024 | |
| dc.description | In today’s world, we heavily rely on smart devices, especially mobile ones, for a multitude of purposes. These cutting-edge gadgets have been developed to be user-centric, serving functions in communication, data exchange, gaming, entertainment, economics, commerce, and numerous other sectors. At the heart of this digital revolution are mobile applications (apps), which cater to an array of functionalities such as banking, entertainment, and [1]. These applications rely on operating systems (OS) to facilitate seamless user interaction with hardware and manage tasks effectively. Android, a globally popular OS, has garnered significant attention for its open-source nature, making it the OS of choice to many smartphone vendors. | |
| dc.description.abstract | The Android operating system has become increasingly popular, not only on mobile phones but also in various other platforms such as Internet-of-Things devices, tablet computers, and wearable devices. Due to its open-source nature and significant market share, Android poses an attractive target for malicious actors. One of the notable security challenges associated with this operating system is riskware. Riskware refers to applications that may pose a security threat due to their vulnerability and potential for misuse. Although riskware constitutes a considerable portion of Android’s ecosystem malware, it has not been studied as extensively as other types of malware such as ransomware and trojans. In this study, we employ machine learning techniques to analyze the behavior of different riskware families and identify similarities in their actions. Furthermore, our research identifies specific behaviors that can be used to distinguish these riskware families. To achieve these insights, we utilize various tools such as k-Means clustering, principal component analysis, extreme gradient boost classifiers, and Shapley additive explanation. Our findings can contribute significantly to the detection, identification, and forensic analysis of Android riskware. Keywords: android; malware; riskware; behavioral analysis; explainable machine learning, XAI | |
| dc.identifier.citation | Alani, M. M., & Alawida, M. (2024). Behavioral Analysis of Android Riskware Families Using Clustering and Explainable Machine Learning. Big Data and Cognitive Computing, 8(12), 171. | |
| dc.identifier.doi | https://doi.org/ 10.3390/bdcc8120171 | |
| dc.identifier.uri | https://repository.adu.ac.ae/handle/1/7467 | |
| dc.language.iso | en | |
| dc.publisher | MDPI | |
| dc.title | Behavioral Analysis of Android Riskware Families Using Clustering and Explainable Machine Learning | |
| dc.type | Article |
