作者: Vincent F. Taylor , Riccardo Spolaor , Mauro Conti , Ivan Martinovic
关键词: Mobile computing 、 Exploit 、 Computer science 、 World Wide Web 、 Network planning and design 、 Encryption 、 Android (operating system) 、 Scalability 、 Network packet 、 Cryptographic protocol
摘要: Automatic fingerprinting and identification of smartphone apps is becoming a very attractive data gathering technique for adversaries, network administrators, investigators marketing agencies. In fact, the list installed on device can be used to identify vulnerable an attacker exploit, uncover victim's use sensitive apps, assist planning, aid marketing. However, app complicated by vast number available download, wide range devices they may on, payload encryption protocols such as HTTPS/TLS. this paper, we present novel methodology framework implementing it, called AppScanner, automatic real-time Android from their encrypted traffic. To build fingerprints, run automatically physical collect traces. We apply various processing strategies these traces before extracting features that are train our supervised learning algorithms. Our fingerprint generation highly scalable does not rely inspecting packet payloads, thus works even when HTTPS/TLS employed. built deployed lightweight ran thorough set experiments assess its performance. profiled 110 most popular in Google Play Store were later able re-identify them with more than 99% accuracy.