MAL-SCAN :ANDROID MALWARE DETECTION BASED ON SOCIAL NETWORK CENTRALITY ANALYSIS

Authors

  • Mrs. J Prashanthi Author
  • Uppu Vamshi Krishna Author
  • Kairamkonda Mahesh Author
  • Vadthya Srikanth Author
  • Katika Muneesh Author

DOI:

https://doi.org/10.64751/9jj24189

Abstract

The rapid expansion of Android-based smartphones, tablets, wearable devices, mobile banking applications, digital payment platforms, social networking services, and enterprise mobility has significantly increased the attack surface available to malicious software. Android malware increasingly employs code obfuscation, repackaging, dynamic payload loading, permission abuse, inter-component communication, hidden API invocation, and coordinated behavioral dependencies to evade conventional signature-based and isolated feature-based detection mechanisms. Traditional Android malware detection methods generally analyze applications as independent collections of permissions, API calls, opcodes, system calls, or behavioral events; however, such approaches may fail to capture the structural relationships among application components and securityrelevant entities. This research proposes MALSCAN, an intelligent Android malware detection framework based on social network centrality analysis, in which an Android application is transformed into a security interaction graph and analyzed using graph-theoretic centrality measures inspired by social network analysis. Nodes represent entities such as application components, permissions, sensitive API calls, intents, services, receivers, URLs, and behavioral events, while edges represent invocation, communication, dependency, permission usage, or information-flow relationships. The framework computes Degree Centrality, Betweenness Centrality, Closeness Centrality, Eigenvector Centrality, and PageRank-based importance scores to identify structurally influential entities and suspicious interaction hubs within an application graph. The resulting centrality profiles are combined with selected static and behavioral indicators and supplied to machine learning classifiers such as Random Forest, Support Vector Machine, XGBoost, and Logistic Regression. A hybrid decision engine produces a malware probability and classifies applications as Benign, Suspicious, or Malicious. The proposed architecture consists of five interconnected layers: Android Application Acquisition, Static Analysis and Security Graph Construction, Social Network Centrality Analysis and Intelligent Detection, Risk Assessment and Response, and Application/User layers. Prototype-oriented evaluation is defined using accuracy, precision, recall, F1-score, graphfeature efficiency, false-positive rate, and detection response time. Illustrative conceptual results indicate that MAL-SCAN can outperform signature-based scanning, conventional permission-based machine learning, and standalone graph analysis by exploiting the structural importance of security-relevant entities. The proposed framework provides a scalable and explainable foundation for Android malware detection in mobile devices, enterprise app stores, application marketplaces, mobile security gateways, and cybersecurity laboratories

Downloads

Published

2026-07-09

How to Cite

MAL-SCAN :ANDROID MALWARE DETECTION BASED ON SOCIAL NETWORK CENTRALITY ANALYSIS. (2026). International Journal of AI Electronics and Nexus Energy, 2(3), 42-53. https://doi.org/10.64751/9jj24189