ANDROID MALWARE CLASSIFICATION APPROACH BASED ON HOST-LEVEL ENCRYPTED TRAFFIC SHAPING

被引:3
|
作者
Zhou, Jie [1 ]
Niu, Weina [1 ]
Zhang, Xiaosong [1 ]
Peng, Yujie [1 ]
Wu, Hao [1 ]
Hu, Teng [1 ]
机构
[1] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu 611731, Peoples R China
基金
中国国家自然科学基金;
关键词
Android malware classification; Host-level traffic; Encrypted traffic analysis; Machine learning; Confusion classifier;
D O I
10.1109/ICCWAMTIP51612.2020.9317429
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of mobile terminals, smartphones have attracted a very huge number of users with their powerful functions. Among them, Android system is famous for its open-source and convenience, which occupies a large market share. But this also leads many attackers to use their malware to gain benefits quickly, which make it necessary to design a practical android malware detection approach. At present, there are not many pieces of research on detecting malware by analyzing Android malicious traffic. This paper examines the characteristics of malicious traffic on the host computer to construct a traffic fingerprint. It combines machine learning algorithms to build a practical detection approach which is also suitable for encrypted traffic. To distinguish similar fuzzy traffic, an additional layer named confusion classifier is added to help further malware classification. This paper uses a real-world dataset called CICAndMal2017 and simulates two classification scenarios: malware binary detection and malware category classification. The experimental results show that the accuracy of the malware binary detection reached 98.8% while the accuracy rate of malware category classification is 95.2%.
引用
收藏
页码:246 / 249
页数:4
相关论文
共 50 条
  • [41] A federated approach to Android malware classification through Perm-Maps
    D'Angelo, Gianni
    Palmieri, Francesco
    Robustelli, Antonio
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2022, 25 (04): : 2487 - 2500
  • [42] Android Malware Detection Methods Based on the Combination of Clustering and Classification
    Xiong, Zhi
    Guo, Ting
    Zhang, Qinkun
    Cheng, Yu
    Xu, Kai
    NETWORK AND SYSTEM SECURITY (NSS 2018), 2018, 11058 : 411 - 422
  • [43] Android Malware Classification using XGBoost based on Images Patterns
    Chen, Huajun
    Du, Ranjin
    Liu, Zhen
    Xu, Huan
    PROCEEDINGS OF 2018 IEEE 4TH INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC 2018), 2018, : 1358 - 1362
  • [44] Android Malware Family Classification Based on Sensitive Opcode Sequence
    Jiang, Jianguo
    Li, Song
    Yu, Min
    Li, Gang
    Liu, Chao
    Chen, Kai
    Liu, Hui
    Huang, Weiqing
    2019 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2019, : 63 - 69
  • [45] Android malware detection technology based on improved Bayesian Classification
    Yu Lu
    Pan Zulie
    Liu Jingju
    Shen Yi
    2013 THIRD INTERNATIONAL CONFERENCE ON INSTRUMENTATION & MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC), 2013, : 1338 - 1341
  • [46] Encrypted Malware Traffic Detection via Graph-based Network Analysis
    Fu, Zhuoqun
    Liu, Mingxuan
    Qin, Yue
    Zhang, Jia
    Zou, Yuan
    Yin, Qilei
    Li, Qi
    Duan, Haixin
    PROCEEDINGS OF 25TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2022, 2022, : 495 - 509
  • [47] A Distance-Based Method for Building an Encrypted Malware Traffic Identification Framework
    Liu, Jiayong
    Tian, Zhiyi
    Zheng, Rongfeng
    Liu, Liang
    IEEE ACCESS, 2019, 7 : 100014 - 100028
  • [48] Opcode-level function call graph based android malware classification using deep learning
    Niu, Weina
    Cao, Rong
    Zhang, Xiaosong
    Ding, Kangyi
    Zhang, Kaimeng
    Li, Ting
    Sensors (Switzerland), 2020, 20 (13): : 1 - 23
  • [49] OpCode-Level Function Call Graph Based Android Malware Classification Using Deep Learning
    Niu, Weina
    Cao, Rong
    Zhang, Xiaosong
    Ding, Kangyi
    Zhang, Kaimeng
    Li, Ting
    SENSORS, 2020, 20 (13) : 1 - 23
  • [50] Tabular-based self-supervised learning approach for encrypted traffic classification
    Zheng, Xuan
    Ma, Xiuli
    Jin, Yanliang
    Gu, Dongsheng
    Wang, Rui
    JOURNAL OF ELECTRONIC IMAGING, 2023, 32 (04)