Enabling Robust Android Malicious Packet Capturing and Detection via Android Kernel

Mingyang Li, Weina Niu, Xinglong Chen, Jiacheng Gong, Kegang Hao, Xiaosong Zhang · 2024

The prevalence of Android malware presents significant challenges to the security of the Android operating system. Malicious packet detection is a critical technique in combating Android malware. Android malicious packet detection often includes packet capturing and detecting the packets through machine learning or deep learning models. Nonetheless, evolving malware with anti-packet capturing measures, disrupts packet capturing and diminishes the performance of malicious packet detection models. To address these challenges, we propose ePacket, a novel framework for capturing Android malicious packet. By leveraging eBPF technology, ePacket captures application level packets from apps at the Android kernel, effectively circumventing anti-packet capturing strategies employed by malware. Additionally, we have compiled a summary of anti-packet capturing strategies observed in real Android malware. We evaluate ePacket using over 3,000 apps. The results demonstrate that ePacket effectively circumvents anti-packet capturing strategies and captures a significantly higher volume of malicious packet (up to 30% more) compared to other three state-of-the-art tools.

Read the paper · More papers on PaperTik