Hierarchical Identifier: Application to User Privacy Eavesdropping on Mobile Payment App

Hierarchical Identifier: Application to User Privacy Eavesdropping on Mobile Payment App
复制标题

分层标识符:在移动支付App用户隐私窃听中的应用

DOI:
10.3390/s19143052
复制
发表时间:
2019
期刊:
Sensor
影响因子:
--
通讯作者:
JianXu
JianXu
中科院分区:
其他
文献类型:
--
作者:
Yaru Wang;NingZheng;MingXu;TongQiao;QiangZhang;FeipengYan;JianXu

文献摘要

被引文献

相似文献

移动的支付应用已经被广泛采用,这给人们的生活带来了极大的便利。但同时,用户的隐私也可能被攻击者窃听和恶意利用。在本文中,我们考虑了攻击者监视移动支付应用程序中用户隐私的可能方法,攻击者旨在通过分析加密的网络流量来识别用户在交易阶段的金融交易。为了实现这一目标,建立了一个分层的身份识别系统,它可以通过三种不同的方式获取用户的隐私信息。首先,它从流量数据中识别移动的支付应用程序,然后对移动的支付应用程序上的特定操作进行分类,最后检测操作中的详细步骤。在我们提出的系统中,我们从移动的支付应用程序上生成的收集的流量数据中提取可靠的特征,然后使用一系列性能良好的集成学习策略来处理三个识别任务。实验结果表明,与现有的工作相比,我们提出的分层识别系统的性能更好。
Mobile payment apps have been widely-adopted, which brings great convenience to people’s lives. However, at the same time, user’s privacy is possibly eavesdropped and maliciously exploited by attackers. In this paper, we consider a possible way for an attacker to monitor people’s privacyonamobilepaymentapp,wheretheattackeraimstoidentifytheuser’sfinancialtransactions at the trading stage via analyzing the encrypted network traffic. To achieve this goal, a hierarchical identification system is established, which can acquire users’ privacy information in three different manners. First, it identifies the mobile payment app from traffic data, then classifies specific actions on the mobile payment app, and finally, detects the detailed steps within the action. In our proposed system, we extract reliable features from the collected traffic data generated on the mobile payment app, then use a series of well-performing ensemble learning strategies to deal with three identification tasks. Compared with prior works, the experimental results demonstrate that our proposed hierarchical identification system performs better.