Characterizing Mobile Applications Through Analysis of DNS Traffic

被引:1
作者
Jimenez-Berenguel, Andrea [1 ]
Moure-Garrido, Marta [1 ]
Garcia-Rubio, Carlos [1 ]
Campo, Celeste [1 ]
机构
[1] Univ Carlos III Madrid, Dept Telemat Engn, Leganes, Madrid, Spain
来源
PROCEEDINGS OF THE INT'L ACM SYMPOSIUM ON PERFORMANCE EVALUATION OF WIRELESS AD HOC, SENSOR, & UBIQUITOUS NETWORKS, PE-WASUN 2023 | 2023年
关键词
Mobile apps characterization; Android apps; User Privacy; DNS traffic; encrypted DNS;
D O I
10.1145/3616394.3618268
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
User privacy may remain vulnerable when using encrypted communication protocols, such as HTTPS, if DNS queries are sent in cleartext over UDP port 53 (Do53). In this study, we demonstrate the possibility of characterizing the mobile application a user is using based on its Do53 traffic. By analyzing a dataset of traffic captured from 80 Android mobile apps, we can identify the app being used based on its DNS queries with an accuracy of 88.75%. While modern operating systems, including Android since version 9.0, support encrypted DNS traffic, this feature is not enabled by default and relies on the DNS provider's support. Moreover, even when DNS traffic is encrypted, the DNS service provider still has access to our queries and could potentially extract information from them.
引用
收藏
页码:69 / 76
页数:8
相关论文
共 44 条
  • [41] Androshield: Automated android applications vulnerability detection, a hybrid static and dynamic analysis approach
    Amin A.
    Eldessouki A.
    Magdy M.T.
    Abdeen N.
    Hindy H.
    Hegazy I.
    Information (Switzerland), 2019, 10 (10):
  • [42] AndroShield: Automated Android Applications Vulnerability Detection, a Hybrid Static and Dynamic Analysis Approach
    Amin, Amr
    Eldessouki, Amgad
    Magdy, Menna Tullah
    Abdeen, Nouran
    Hindy, Hanan
    Hegazy, Islam
    INFORMATION, 2019, 10 (10)
  • [43] Security analysis of menstruation cycle tracking applications using static, dynamic and machine learning techniques
    Deverashetti, Mounika
    Ranjitha, K.
    Pradeepthi, K., V
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 67
  • [44] An Empirical Analysis of Test Input Generation Tools for Android Apps through a Sequence of Events
    Yasin, Husam N.
    Ab Hamid, Siti Hafizah
    Yusof, Raja Jamilah Raja
    Hamzah, Muzaffar
    SYMMETRY-BASEL, 2020, 12 (11): : 1 - 27