On-Device Detection of Repackaged Android Malware via Traffic Clustering

Joint Authors

He, Gaofeng
Xu, Bingfeng
Zhu, Haiting
Zhang, Lu

Source

Security and Communication Networks

Issue

Vol. 2020, Issue 2020 (31 Dec. 2020), pp.1-19, 19 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2020-05-31

Country of Publication

Egypt

No. of Pages

19

Main Subjects

Information Technology and Computer Science

Abstract EN

Malware has become a significant problem on the Android platform.

To defend against Android malware, researchers have proposed several on-device detection methods.

Typically, these on-device detection methods are composed of two steps: (i) extracting the apps’ behavior features from the mobile devices and (ii) sending the extracted features to remote servers (such as a cloud platform) for analysis.

By monitoring the behaviors of the apps that are running on mobile devices, available methods can detect suspicious applications (simply, apps) accurately.

However, mobile devices are typically resource limited.

The feature extraction and massive data transmission might consume substantial power and CPU resources; thus, the performance of mobile devices will be degraded.

To address this issue, we propose a novel method for detecting Android malware by clustering apps’ traffic at the edge computing nodes.

First, a new integrated architecture of the cloud, edge, and mobile devices for Android malware detection is presented.

Then, for repackaged Android malware, the network traffic content and statistics are extracted at the edge as detection features.

Finally, in the cloud, similarities between apps are calculated, and the similarity values are automatically clustered to separate the original apps and the malware.

The experimental results demonstrate that the proposed method can detect repackaged Android malware with high precision and with a minimal impact on the performance of mobile devices.

American Psychological Association (APA)

He, Gaofeng& Xu, Bingfeng& Zhang, Lu& Zhu, Haiting. 2020. On-Device Detection of Repackaged Android Malware via Traffic Clustering. Security and Communication Networks،Vol. 2020, no. 2020, pp.1-19.
https://search.emarefa.net/detail/BIM-1208571

Modern Language Association (MLA)

He, Gaofeng…[et al.]. On-Device Detection of Repackaged Android Malware via Traffic Clustering. Security and Communication Networks No. 2020 (2020), pp.1-19.
https://search.emarefa.net/detail/BIM-1208571

American Medical Association (AMA)

He, Gaofeng& Xu, Bingfeng& Zhang, Lu& Zhu, Haiting. On-Device Detection of Repackaged Android Malware via Traffic Clustering. Security and Communication Networks. 2020. Vol. 2020, no. 2020, pp.1-19.
https://search.emarefa.net/detail/BIM-1208571

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1208571