Android Malware Network Behavior Analysis at HTTP Protocol Packet Level

被引:1
|
作者
Wang, Shanshan [1 ]
Hou, Shifeng [2 ]
Zhang, Lei [1 ]
Chen, Zhenxiang [1 ]
Han, Hongbo [1 ]
机构
[1] Univ Jinan, Sch Informat Sci & Engn, Jinan 250022, Peoples R China
[2] Lib Rizhao Polytech, Rizhao 276826, Peoples R China
关键词
Android; Malware; Network traffic; Analyze; Detection;
D O I
10.1007/978-3-319-27161-3_45
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Smart phones, particularly the ones based on Android, have become the most popular devices. The surfing habits of users have been changed from the traditional PC terminal to mobile terminal officially. However, the mobile terminal application exposes more and more problems. Two common ways to analyze malware are source code analysis and dynamic behavior analysis. Researchers pay little attention to the network traffic generated by mobile terminal application. Nevertheless, shell technology makes source code analysis difficult while dynamic behavior analysis consumes too much resource. In fact, normal application and malware perform differently at the network level. We found that the features of HTTP packet are dramatically different in normal traffic and malicious traffic dataset. The application analysis from the perspective of network traffic can provide us a new way to detect malware.
引用
收藏
页码:497 / 507
页数:11
相关论文
共 50 条
  • [1] Android Malware Clustering Analysis on Network-Level Behavior
    Wang, Shanshan
    Chen, Zhenxiang
    Li, Xiaomei
    Wang, Lin
    Ji, Ke
    Zhao, Chuan
    INTELLIGENT COMPUTING THEORIES AND APPLICATION, ICIC 2017, PT I, 2017, 10361 : 796 - 807
  • [2] An Analysis of Android Malware Behavior
    Singh, Gagandeep
    Jaafar, Fehmi
    Zavarsky, Pavol
    2018 IEEE 18TH INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C), 2018, : 505 - 512
  • [3] Syntax and behavior semantics analysis of network protocol of malware
    Ying L.-Y.
    Yang Y.
    Feng D.-G.
    Su P.-R.
    Ruan Jian Xue Bao/Journal of Software, 2011, 22 (07): : 1676 - 1689
  • [4] Clustering Android Malware Families by Http Traffic
    Aresu, Marco
    Ariu, Davide
    Ahmadi, Mansour
    Maiorca, Davide
    Giacinto, Giorgio
    2015 10TH INTERNATIONAL CONFERENCE ON MALICIOUS AND UNWANTED SOFTWARE (MALWARE), 2015, : 128 - 135
  • [5] Network Traffic Analysis for Android Malware Detection
    Gaviria de la Puerta, Jose
    Pastor-Lopez, Iker
    Sanz, Borja
    Bringas, Pablo G.
    HYBRID ARTIFICIAL INTELLIGENT SYSTEMS, HAIS 2019, 2019, 11734 : 468 - 479
  • [6] Design on Android malware behavior analysis system
    Li, J.-H. (jovistar@gmail.com), 1600, Beijing University of Posts and Telecommunications (37):
  • [7] Malware Detection in Android by Network Traffic Analysis
    Zaman, Mehedee
    Siddiqui, Tazrian
    Amin, Mohammad Rakib
    Hossain, Md Shohrab
    2015 INTERNATIONAL CONFERENCE ON NETWORKING SYSTEMS AND SECURITY (NSYSS), 2015, : 183 - 187
  • [8] A collaborative approach on host and network level android malware detection
    Bae, Chanwoo
    Shin, Seungwon
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) : 5639 - 5650
  • [9] Understanding the Market-level and Network-level Behaviors of the Android Malware Ecosystem
    Yang, Chao
    Zhang, Jialong
    Gu, Guofei
    2017 IEEE 37TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2017), 2017, : 2452 - 2457
  • [10] A Design of Network Behavior-Based Malware Detection System for Android
    Qi, Yincheng
    Cao, Mingjing
    Zhang, Can
    Wu, Ruping
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2014, PT II, 2014, 8631 : 590 - 600