A Host and Network Based Intrusion Detection for Android Smartphones
Kanishka Ariyapala, Giang Hoang, Ngoc Anh Huynh, Keong Ng Wee, Mauro Conti · 2016
The increased computation and storage capabilities of smartphones have attracted more and more cybercriminals to write mobile malware for different purposes. Due to the popularity of smartphones in both personal life and business, it is empowering an emerging mobile security threat issue. In this paper, we present an intrusion detection system that incorporates not only network features but also host-based information to detect mobile malware. A mobile application is developed to capture host-based features such as CPU usage, battery consumption, running processes, network connections, user activity and network traffic. All these monitored data is sent to a processing server for analysis, to relieve the smartphone from the processing burden. Our system uses netflow based clustering to identify anomalies and correlates further with the host-based features to verify malware intrusions in the Android system.