Real-time Android malware detection using Graph Isomorphism Network and statistical network traffic features
Tung Bui, Minh Tran, Duc Tran, Linh Giang Nguyen · Journal of Cyber Security Technology · 2025
The proliferation of Android malware, driven by the platform’s open nature and widespread use, poses significant security threats to mobile devices. Recently, despite numerous research studies that have introduced machine learning-based malware detection and classification models, these models have not yet simultaneously satisfied the requirements for high accuracy and timely detection capability. This paper introduces a novel model for malware detection leveraging dynamic network traffic analysis and Graph Neural Networks (GNN). Our method utilizes a sliding window strategy to extract both statistical flow features and graph-based structural representations, enabling precise and efficient detection. By combining the Graph Isomorphism Network algorithm with enriched node attributes, the model effectively captures complex malware behaviors. Evaluated on the CIC-AndMal2017 dataset, the approach achieves impressive results, with an inference time of approximately 0.06 s, 99.86% accuracy in malware detection, and 98.94% in malware category classification, outperforming baseline methods. This work demonstrates the potential of GNN-based models in Android malware detection and sets the stage for future advancements in adaptability and real-time deployment.