Leveraging Zero-Payload Packets to Detect Mobile Malware based on Network Traffic
Ruihai Ge, Yongzheng Zhang, Shuhao Li, Guoqiao Zhou, Guangze Zhao · 2022
The rapid growth of mobile malicious applications (apps) poses a serious threat to cyber security. The vast majority of malicious apps steal user data and launch remote attacks via network communications. Existing traffic-based malware detection methods exhibit unsatisfying resource consumption and user privacy leakage in the malware detection process. In this paper, we propose ZeroTraffic, a lightweight but effective detection approach by taking full advantage of zero-payload packets in the TCP protocol. The key insight of our research is that zero-payload packets can be used to reconstruct the behavior patterns of malicious traffic, which differs significantly from benign traffic in terms of communication periodicity and asymmetry of upstream and downstream data. Hence, we can leverage the statistical characteristics based on zero-payload packets to detect mobile malware. In ZeroTraffic, we first summarize and extract the source-oriented and destination-oriented statistical features to enhance the feature expression ability for lightweight data, and then train supervised learning algorithms to build a detector. Note that our model does not involve any user privacy information during its training and detection process. To evaluate the performance of the proposed model, we conduct experiments on a publicly available Andrubis dataset. Experimental results reveal that our method achieves 94.60% accuracy. Besides, our method is superior to a state-of-the-art method in terms of accuracy, precision, recall, and F1-score.