The rapid growth of Android applications has significantly increased the risk of malware capable of
intercepting SMS-based One-Time Passwords (OTPs), leading to financial fraud, identity theft, and unauthorized access
to sensitive user accounts. Traditional Android malware detection approaches primarily rely on static permission analysis
or signature-based detection techniques, which are often insufficient to identify emerging malware variants and
applications requesting excessive sensitive permissions. To address these limitations, this paper proposes a Hybrid Static–
Dynamic Analysis Framework for Detecting SMS-OTP Interception Malware on Android Devices. The proposed
framework integrates Python, Flask, Androguard, Android Studio, Java, Android SDK, and Android PackageManager
APIs to perform APK analysis, permission extraction, installed application analysis, risk score calculation, and security
report generation. Static analysis examines uploaded APK files by extracting manifest information, application
components, and sensitive permissions, while the device-level analysis module evaluates installed Android applications
using PackageManager APIs to identify risky permissions and calculate security scores. The framework classifies
applications into Safe, Medium Risk, and High Risk categories based on predefined risk assessment rules and generates
comprehensive security reports for end users. Experimental results demonstrate that the proposed framework effectively
identifies security-sensitive applications, improves Android security awareness, and provides an economical solution for
Android malware assessment suitable for academic research and practical mobile security applications.
R. Sridevi, Soumya Erra· International Journal of Inn...· 0 citations
Traditional remote access solutions such as VPNs authenticate users only at login and then grant broad
internal network access, exposing organizations to credential theft and lateral movement attacks. This paper proposes a
Zero-Trust Secure Remote Access Framework that continuously verifies device identity and security posture before
granting access. Mutual TLS (mTLS) restricts connectivity to organization-registered devices through certificate-based
authentication, while a Device Posture Agent continuously evaluates antivirus, firewall, operating-system update, and
disk-encryption status. The collected posture data is evaluated by a FastAPI-based Policy Engine, which grants
application-level access only to compliant devices and redirects non-compliant devices for remediation. Unlike VPNs,
which expose the entire internal network, the proposed framework restricts access to individual applications.
Experimental results confirm that the framework correctly authenticates registered devices, detects posture violations in
real time, and enforces dynamic ALLOW/REMEDIATE/DENY decisions, demonstrating a practical and scalable
approach to Zero-Trust remote access.
Syed Sufyaanuddin, R. Sridevi· International Journal of Inn...· 0 citations
By integrating distributed learning, federated learning, homomorphic encryption, and blockchain into a unified framework, the proposed system provides a scalable, secure, and privacy-preserving solution for next-generation cyber forensic intelligence.
R. Sridevi, P. Kumar· International Journal of Inn...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.