<p>This study addresses the critical challenge of detecting Android spyware in real time, emphasizing cybersecurity risks and the limitations of existing approaches. Previous works rely on signature-based methods or static network traffic analysis, which are effective for known spyware but fail to capture dynamic and evolving spyware behaviors in real-time environments. This study bridges this gap by proposing real-time spyware classification approach based on network traffic analysis, utilizing directional features and rule-based labeling for enhancing spyware classification. It collects 14 spyware types with normal traffic and develops two methods: Method A (single directional) and Method B (bi-directional), applying several learning models to assess performance. Models are saved during batch processing for micro-batch and real-time analysis. Using 150 packets, micro-batch accuracy achieves 76.29<InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="11227_2025_7391_Article_IEq1.gif" Format="GIF" Height="13" Rendition="HTML" Resolution="72" Type="Linedraw" Width="19" /> </InlineMediaObject> <EquationSource Format="TEX">\(-\)</EquationSource> <EquationSource Format="MATHML"><math> <mo>-</mo> </math></EquationSource> </InlineEquation>84.95% (Method A) and 74.18<InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="11227_2025_7391_Article_IEq1.gif" Format="GIF" Height="13" Rendition="HTML" Resolution="72" Type="Linedraw" Width="19" /> </InlineMediaObject> <EquationSource Format="TEX">\(-\)</EquationSource> <EquationSource Format="MATHML"><math> <mo>-</mo> </math></EquationSource> </InlineEquation>83.23% (Method B), while real-time analysis achieves 74.99% (Method A) and 72.66% (Method B). XGB achieves 80.01% accuracy, advancing Android spyware classification.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Directional features and rule-based labeling for real-time network traffic-based android spyware classification

  • Mousumi Ahmed Mimi,
  • Hu Ng,
  • Timothy Tzen Vun Yap

摘要

This study addresses the critical challenge of detecting Android spyware in real time, emphasizing cybersecurity risks and the limitations of existing approaches. Previous works rely on signature-based methods or static network traffic analysis, which are effective for known spyware but fail to capture dynamic and evolving spyware behaviors in real-time environments. This study bridges this gap by proposing real-time spyware classification approach based on network traffic analysis, utilizing directional features and rule-based labeling for enhancing spyware classification. It collects 14 spyware types with normal traffic and develops two methods: Method A (single directional) and Method B (bi-directional), applying several learning models to assess performance. Models are saved during batch processing for micro-batch and real-time analysis. Using 150 packets, micro-batch accuracy achieves 76.29 \(-\) - 84.95% (Method A) and 74.18 \(-\) - 83.23% (Method B), while real-time analysis achieves 74.99% (Method A) and 72.66% (Method B). XGB achieves 80.01% accuracy, advancing Android spyware classification.