3.1.1. CICAndMal2017

The CICAndMal2017 was developed by Canadian Institute; the Cybersecurity dataset is a standard mobile malware dataset containing static and dynamic features of log files. The dataset was generated from 80 network flows using CICFlowMeter-V1 and CICFlowMeter-V3. To examine the proposed system, 667 Android malware packets consisting of 413 features were considered for the injection of malicious and normal packets. The dataset is available from this link: https://www.kaggle.com/saurabhshahane/android-permissiondataset, (accessed on 25 November 2021).

**Figure 4.** Percentage of classes of the datasets (**a**) CICAndMal2017 and (**b**) Drebin.

### 3.1.2. The Drebin Dataset

The Drebin dataset was extracted from 15,037 applications of the Drebin project, which contains 215 features and the injection of 5560 malware and 9476 normal applications. The dataset was developed by the Drebin project and published as the DroidFusion paper in the *IEEE Transactions on Cybernetics* journal [59]. The dataset was generated with different Android applications and is available through the following link: https: //www.kaggle.com/shashwatwork/android-malware-dataset-for-machine-learning (accessed on 25 Novmber 2021).
