Abstract
This study developed a context-specific cybersecurity framework for mitigating Android malware and masquerade attacks on aviation training devices. It assessed the level of awareness of aviation training device users regarding Android malware, masquerade attacks, and public education and interventions, and determined usersโ perceptions of permission-based and anomaly-based detection approaches. The study employed a descriptive survey design coupled with applied research. Fifty-one qualified Android users from the Maintenance Training Program and On-the-Job Training of an aviation training organization participated in the study. A structured questionnaire was administered through Google Forms and formally reviewed by seven experts in Information Technology and Cybersecurity for face and content validity. Descriptive statistics, including frequency, percentage, weighted mean, and ranking, were used to analyze the responses. The results showed that respondents were moderately aware of Android malware (overall mean = 2.92) and masquerade attacks (overall mean = 2.74). Awareness of public education and interventions was also moderate (mean = 3.39), although respondents showed a strong willingness to engage in cybersecurity practices when better informed (mean = 4.10). Perceptions of permission-based detection were favorable (mean = 3.41), while anomaly-based detection received a stronger favorable rating (mean = 3.82). The findings indicate that users recognized the risks associated with mobile threats but had gaps in threat recognition, confidence, and preparedness. Based on the empirical findings and reviewed literature, the researcher developed the MAPER FrameworkโMonitor, Assess, Prevent, Educate, and Respond. The framework integrates technical safeguards, risk assessment, preventive controls, cybersecurity education, and incident response into a practical mitigation approach for Android devices used in aviation training.
Keywords: Android Malware; Masquerade Attacks; Cybersecurity Awareness; Permission-Based Detection; Anomaly-Based Detection; Aviation Training; MAPER Framework
1. Introduction
The increasing use of smartphones and tablets has changed how people communicate, learn, work, and access digital information. Mobile devices are now used not only for personal activities but also for education, training, communication, and access to technical resources. This increased dependence creates a corresponding need to address mobile cybersecurity risks, particularly Android malware and attacks that disguise malicious applications as legitimate software.
2. Methodology
The study employed a descriptive survey research design coupled with applied research. The descriptive component was used to determine existing levels of awareness and perceptions without manipulating the respondents or study conditions. The applied research component was used to translate the empirical findings and reviewed literature into a practical cybersecurity mitigation framework.
3. Results and Discussion
The respondentsโ overall awareness of Android malware was 2.92, interpreted as Moderately Aware. The highest-rated indicator concerned awareness of the possible consequences of malware infection, such as data theft, financial loss, or system damage (mean = 3.50). Regular updating of antivirus or anti malware software received a mean of 3.10, while familiarity with the term malware received 2.80. The lowest-rated indicator was confidence in recognizing potential signs of malware infection (mean = 2.20). This pattern suggests that respondents understood that malware can cause harm but were less confident in identifying an actual infection. The finding supports the capstone literature emphasizing the importance of examining application permissions and device behavior and reinforces the need for practical cybersecurity education.
4. Conclusion
The study found that aviation training device users had moderate awareness of Android malware, masquerade attacks, and public education and interventions. Although respondents recognized the potential risks associated with mobile threats, the results revealed limitations in their confidence, threat recognition, and preparedness to respond. The strongest awareness-related finding was the respondentsโ willingness to engage in cybersecurity practices when better informed, indicating a positive opportunity for continuous and practical cybersecurity education.
References
[1] Aonzo, S., Georgiu, G. C., Verderame, L., & Merlo, A. (2020). Obfuscapk: An open source black-box obfuscation tool for Android apps. IEEE Security & Privacy, 18(3).
[2] Aso, A., Ono, M., & Yoshida, T. (2018). Mobile malware: A survey on security threats and countermeasures. IEEE Access, 6, 66325โ66340.
[3] Chen, J., Xue, Y., Chen, Y., Tian, K., Jia, W., & Liu, B. (2019). Understanding user behavior of Android app installation. IEEE Transactions on Mobile Computing, 18(3), 593โ606.
[4] Chiew, K. L., et al. (2023). Mitigation strategies against phishing attacks: A systematic literature review. Computers & Security, 132, 103387.
[5] Ehsan, A., Catal, C., & Mishra, A. (2022). Detecting malware by analyzing app permissions on Android platform: A systematic literature review. Sensors, 22(20), 7928.
Full reference list available in the PDF version.