H-PINTDroid: Hybrid Android Malware Detection Using Permissions, Intents and Network Traffic

Anshul Arora · 2025

Android malware pose serious threats to the user community as they can steal private or confidential information stored on the mobile device, or even damage it. In 2024, security companies, such as Kaspersky, detected more than 300,000 malicious Android apps posing serious threats to Android devices and users. Thus, malware detection on Android has become an important research topic. Some detection methods are based on static analysis, which employs static features such as permissions and intents. In contrast, others are based on dynamic analysis, which utilizes dynamic features like network traffic. In this paper, we propose a hybrid Android malware detector, named H-PINTDroid, which combines static permissions and intents with dynamic network traffic. To the best of our knowledge, no other research work in the literature has combined static permissions and static intents with dynamic network traffic to detect malware on the Android mobile operating system. We applied several machine learning and deep learning techniques, incorporating hybrid features, to a large dataset comprising 40,000 malware apps and 45,000 normal apps. Our experimental results demonstrate that the hybrid combination of static and dynamic features gives us a better detection rate than using these features individually.

Read the paper · More papers on PaperTik