Mobile Malware Network Packet Detection System based on SVM

碩士 === 銘傳大學 === 資訊傳播工程學系碩士班 === 105 === Smart phones have become very popular recently. People get used to storing personal profiles such as contact information, email account and password, into their mobile devices. Almost all mobile phones used either Android or IOS operation system. People re...

Full description

Bibliographic Details
Main Authors: TAN, GENG-LUN, 譚庚倫
Other Authors: CHIANG, CHING-CHUAN
Format: Others
Language:zh-TW
Published: 2017
Online Access:http://ndltd.ncl.edu.tw/handle/22019794505066543690
id ndltd-TW-105MCU00676006
record_format oai_dc
spelling ndltd-TW-105MCU006760062017-06-29T04:42:50Z http://ndltd.ncl.edu.tw/handle/22019794505066543690 Mobile Malware Network Packet Detection System based on SVM 以SVM為基礎之手機惡意封包偵測系統 TAN, GENG-LUN 譚庚倫 碩士 銘傳大學 資訊傳播工程學系碩士班 105 Smart phones have become very popular recently. People get used to storing personal profiles such as contact information, email account and password, into their mobile devices. Almost all mobile phones used either Android or IOS operation system. People relying on mobile because of the convenience and functions. However there are some problems while using the mobile including mobile security. Android system is an open source, hence it allows the apps which are not authenticated by official company to be installed into user’s mobile phone. Because of the above reasons, the hackers’ attacking target starts to switch from PC to mobile phones. The hackers steal the user’s private information form user’s mobile devices with malware apps, or send the malware code to user’s phones to execute attack job. This research proposes an agent-based malware network packet detection system. The system employs agent app to periodically collect user’s network packets and store the packets into the pcap file. It then transfers the pcap file which stores the GET protocol packets to a remote server and stores GET protocol packet’s content into the database. The GET packet content in database is analyzed with Support Vector Machine (SVM) to predict the malware behavior. LibSVM and Scikit-learn are used to model the collected GET protocol packet’s contents, and their performances are compared in the thesis. This proposed system also provides interfaces including Agent App and website, which shows the results of the analysis, the history management and model management for the query of users. CHIANG, CHING-CHUAN HSIEH, CHAUR-HEH 江清泉 謝朝和 2017 學位論文 ; thesis 67 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 銘傳大學 === 資訊傳播工程學系碩士班 === 105 === Smart phones have become very popular recently. People get used to storing personal profiles such as contact information, email account and password, into their mobile devices. Almost all mobile phones used either Android or IOS operation system. People relying on mobile because of the convenience and functions. However there are some problems while using the mobile including mobile security. Android system is an open source, hence it allows the apps which are not authenticated by official company to be installed into user’s mobile phone. Because of the above reasons, the hackers’ attacking target starts to switch from PC to mobile phones. The hackers steal the user’s private information form user’s mobile devices with malware apps, or send the malware code to user’s phones to execute attack job. This research proposes an agent-based malware network packet detection system. The system employs agent app to periodically collect user’s network packets and store the packets into the pcap file. It then transfers the pcap file which stores the GET protocol packets to a remote server and stores GET protocol packet’s content into the database. The GET packet content in database is analyzed with Support Vector Machine (SVM) to predict the malware behavior. LibSVM and Scikit-learn are used to model the collected GET protocol packet’s contents, and their performances are compared in the thesis. This proposed system also provides interfaces including Agent App and website, which shows the results of the analysis, the history management and model management for the query of users.
author2 CHIANG, CHING-CHUAN
author_facet CHIANG, CHING-CHUAN
TAN, GENG-LUN
譚庚倫
author TAN, GENG-LUN
譚庚倫
spellingShingle TAN, GENG-LUN
譚庚倫
Mobile Malware Network Packet Detection System based on SVM
author_sort TAN, GENG-LUN
title Mobile Malware Network Packet Detection System based on SVM
title_short Mobile Malware Network Packet Detection System based on SVM
title_full Mobile Malware Network Packet Detection System based on SVM
title_fullStr Mobile Malware Network Packet Detection System based on SVM
title_full_unstemmed Mobile Malware Network Packet Detection System based on SVM
title_sort mobile malware network packet detection system based on svm
publishDate 2017
url http://ndltd.ncl.edu.tw/handle/22019794505066543690
work_keys_str_mv AT tangenglun mobilemalwarenetworkpacketdetectionsystembasedonsvm
AT tángēnglún mobilemalwarenetworkpacketdetectionsystembasedonsvm
AT tangenglun yǐsvmwèijīchǔzhīshǒujīèyìfēngbāozhēncèxìtǒng
AT tángēnglún yǐsvmwèijīchǔzhīshǒujīèyìfēngbāozhēncèxìtǒng
_version_ 1718479683291447296