DocumentCode
3777059
Title
Mining network traffic for application category recognition on Android platform
Author
Songjie Wei; Gaoxiang Wu; Ziyang Zhou;Ling Yang
Author_Institution
School of Computer Science and Engineering, Nanjing University of Science and Technology, 200 Xiaolingwei, 210094, China
fYear
2015
Firstpage
409
Lastpage
413
Abstract
Signature-based static mobile malware detection is fragile when facing code obfuscation and transformation attacks. Behavior based malware detection mechanisms have been widely studied and experimented. So far only the application´s running behaviors, such as API calls and resource consumption are used, which can also be easily concealed and obfuscated with various coding tricks. Most mobile malware need either cellular or network connection to conduct their malicious activities. We propose to monitor an application´s network behavior and interaction to characterize application behaviors. An integrated testbed system has been designed and prototyped for such network behavior collection. Statistical features are derived from application network traffic, which are further fed to a machine-learning based classifier to build one general model for each typical category of mobile applications. Experiments show that applications in each category with identical functionality exhibit similar network behaviors, which makes it possible to use the derived category model of network behaviors to evaluate future unknown application for its trustworthiness.
Keywords
"Portals","Monitoring","Internet","Firewalls (computing)","Malware","Privacy"
Publisher
ieee
Conference_Titel
Progress in Informatics and Computing (PIC), 2015 IEEE International Conference on
Print_ISBN
978-1-4673-8086-7
Type
conf
DOI
10.1109/PIC.2015.7489879
Filename
7489879
Link To Document