AppSniffer: Towards Robust Mobile App Fingerprinting Against VPN
Sanghak Oh, Minwook Lee, Hyunwoo Lee, Elisa Bertino, Hyoungshick Kim
摘要
Application fingerprinting is a useful data analysis technique for network administrators, marketing agencies, and security analysts. For example, an administrator can adopt application fingerprinting techniques to determine whether a user’s network access is allowed. Several mobile application fingerprinting techniques (e.g., FlowPrint, AppScanner, and ET-BERT) were recently introduced to identify applications using the characteristics of network traffic. However, we find that the performance of the existing mobile application fingerprinting systems significantly degrades when a virtual private network (VPN) is used. To address such a shortcoming, we propose a framework dubbed AppSniffer that uses a two-stage classification process for mobile app fingerprinting. In the first stage, we distinguish VPN traffic from normal traffic; in the second stage, we use the optimal model for each traffic type. Specifically, we propose a stacked ensemble model using Light Gradient Boosting Machine (LightGBM) and a FastAI library-based neural network model to identify applications’ traffic when a VPN is used. To show the feasibility of AppSniffer, we evaluate the detection accuracy of AppSniffer for 150 popularly used Android apps. Our experimental results show that AppSniffer effectively identifies mobile applications over VPNs with F1-scores between 84.66% and 95.49% across four different VPN protocols. In contrast, the best state-of-the-art method (i.e., AppScanner) demonstrates significantly lower F1-scores between 25.63% and 47.56% in the same settings. Overall, when normal traffic and VPN traffic are mixed, AppSniffer achieves an F1-score of 90.63%, which is significantly better than AppScanner that shows an F1-score of 70.36%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Towards Context-Aware Traffic Classification via Time-Wavelet Fusion NetworkZiming Zhao, Zhuoxue Song, Xiaofei Xie, Zhaoxuan Li 等KDD 2025 · 被引用 5 次
- Defending against Traffic Analysis Attacks with Flexible In-Network ObfuscationGuorui Xie, Qing Li, Zhenning Shi, Gianni Antichi 等NSDI 2026 · 被引用 2 次
- Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeShan Wang, Ming Yang, Yu Liu, Yue Zhang 等CCS 2025
- SoK: Decoding the Enigma of Encrypted Network Traffic ClassifiersNimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. JhaS&P 2025
它引用的顶会 Paper5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- WireGuard: Next Generation Kernel Network TunnelJason A. DonenfeldNDSS 2017 · 被引用 259 次
- TLS 1.3 in Practice: How TLS 1.3 Contributes to the InternetHyunwoo Lee, Doowon Kim, Yonghwi KwonWWW 2021 · 被引用 47 次
- Programmable In-Network Security for Context-aware BYOD PoliciesQiao Kang, Lei Xue, Adam Morrison, Yuxin Tang 等USENIX Security 2020
- OpenVPN is Open to VPN FingerprintingDiwen Xue, Reethika Ramesh, Arham Jain, Michalis Kallitsis 等USENIX Security 2022
相关 Paper
- FlowPrint: Semi-Supervised Mobile-App Fingerprinting on Encrypted Network TrafficThijs van Ede, Riccardo Bortolameotti, Andrea Continella, Jingjing Ren 等NDSS 2020
- Practical VPN Fingerprinting using Coarse Inference of Field Specifications in Data ChannelsTaewook Kim, Jinhwan Kim, Sangmin Lee, Yeongpil ChoINFOCOM 2026
- DecETT: Accurate App Fingerprinting Under Encrypted Tunnels via Dual Decouple-based Semantic EnhancementZheyuan Gu, Chang Liu, Xiyuan Zhang, Chen Yang 等WWW 2025 · 被引用 2 次
- Identifying VPN Servers through Graph-Represented BehaviorsChenxu Wang, Jiangyi Yin, Zhao Li, Hongbo Xu 等WWW 2024 · 被引用 6 次
- Packet-Level Open-World App Fingerprinting on Wireless TrafficJianfeng Li, Shuohan Wu, Hao Zhou, Xiapu Luo 等NDSS 2022
