DroidSentry: A Survey of Android Malware Dynamic Analysis Techniques

Authors

Mrs. Amritha R

Assistant professor, Department of CSE, K.S Institute of Technology, Bangaluru, India (India)

Shashank Gowda U.

Student, Department of CSE, K.S Institute of Technology, Bangaluru, India (India)

Rudresh S C.,

Student, Department of CSE, K.S Institute of Technology, Bangaluru, India (India)

Sanketh Kumar K R.

Student, Department of CSE, K.S Institute of Technology, Bangaluru, India (Indiai)

Darshan K R

Student, Department of CSE, K.S Institute of Technology, Bangaluru, India (India)

Article Information

DOI: 10.51244/IJRSI.2026.1305000168

Subject Category: Android security

Volume/Issue: 13/5 | Page No: 1876-1885

Publication Timeline

Submitted: 2026-05-07

Accepted: 2026-05-12

Published: 2026-06-05

Abstract

The rapid evolution of Android malware has severely undermined the efficacy of conventional analysis methodologies. Static analysis is frequently circumvented by advanced code obfuscation, native JNI exploitation, and dynamic payload loading architectures. Concurrently, dynamic analysis conducted within virtualized sandboxes is increasingly neutralized by sophisticated virtual machine (VM) evasion techniques that detect artificial execution environments. This survey provides a comprehensive taxonomy of Android malware analysis approaches, critically evaluating their capabilities and limitations. We systematically identify three persistent gaps in the current literature: (1) the consistent failure of virtualized execution environments against evasion-aware malware; (2) the absence of active adversarial API response tampering as a recognized analysis vector; and (3) the inaccessibility of complex forensic output to non-specialist analysts.
Building upon this gap analysis, we present the design rationale and architecture of DroidSentry, a Hardware-in-the-Loop (HIL) adversarial dynamic analysis framework. DroidSentry addresses these gaps through authentic physical-device-based execution, active mitmproxy-driven response manipulation via Gnirehtet reverse tethering, and experimental AI-assisted forensic narration via a locally hosted Llama 3 Large Language Model. By deploying on a Linux-based orchestration host coupled with a physical Android node, the framework significantly reduces environmental fingerprinting. Comparative analysis against representative existing tools demonstrates DroidSentry's effectiveness at the intersection of physical execution authenticity, adversarial testing depth, and forensic explainability.

Keywords

Android Malware, Dynamic Analysis, Hardware-in-the-Loop, VM Evasion, mitmproxy, AI Forensic Narration, Gnirehtet, Magisk.

Downloads

References

1. Statcounter. (2024). Mobile Operating System Market Share Worldwide. StatCounter Global Stats. [Google Scholar] [Crossref]

2. Xi, N., Qin, X., Chen, H., & Li, J. (2025). GNNDROID: Graph-Learning Based Malware Detection for Android Apps with Native Code. IEEE Transactions on Dependable and Secure Computing, 22(2). [Google Scholar] [Crossref]

3. Almarri, S., Branch, P., & Valli, C. (2025). A Review of the Recent Trends in Mobile Malware Evolution, Detection, and Analysis. IEEE Access, 13. [Google Scholar] [Crossref]

4. Feng, P., Ma, J., Sun, C., Xu, X., & Ma, Y. (2018). A Novel Dynamic Android Malware Detection System with Ensemble Learning. IEEE Access, 6, 1-16. [Google Scholar] [Crossref]

5. Enck, W., et al. (2014). TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones. ACM Transactions on Computer Systems, 32(2), Article 5. [Google Scholar] [Crossref]

6. Tam, S., Feizollah, A., Anuar, N. B., Salleh, R., & Cavallaro, L. F. (2017). The Evolution of Android Malware and Android Analysis Techniques. ACM Computing Surveys, 49(4), Article 76. [Google Scholar] [Crossref]

7. mitmproxy contributors. (2024). mitmproxy: An Interactive TLS-capable Intercepting HTTP Proxy. [Google Scholar] [Crossref]

8. Genymobile. (2023). Gnirehtet: Reverse Tethering over ADB for Android. GitHub Repository. [Google Scholar] [Crossref]

9. Ollama contributors. (2024). Ollama: Get Up and Running With Large Language Models Locally. [Google Scholar] [Crossref]

10. Desnos, A., & Gueguen, G. (2011). Android: From Reversing to Decompilation. In Proceedings of Black Hat Abu Dhabi. [Google Scholar] [Crossref]

11. Xue, L., Zhou, Y., Chen, T., Luo, X., & Gu, G. (2017). Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ART. In Proceedings of the 26th USENIX Security Symposium, 289-306. [Google Scholar] [Crossref]

12. Zhou, Y., & Jiang, X. (2012). Dissecting Android Malware: Characterization and Evolution. In Proceedings of the IEEE Symposium on Security and Privacy, 95-109. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles