Towards a Hybrid Intrusion Detection System for Android-based PPDR terminals

Pedro Borges, Bruno Sousa, Luis Ferreira, Firooz B. Saghezchi, Georgios Mantas, Jose Ribeiro, Jonathan Rodriguez, Luis Cordeiro, Paulo Simoes

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

9 Citations (Scopus)

Abstract

Mobile devices are used for communication and for tasks that are sensitive and subject to tampering. Indeed, attacks can be performed on the users' devices without user awareness, this represents additional risk in mission critical scenarios, such as Public Protection and Disaster Relief (PPDR). Intrusion Detection Systems are important for scenarios where information leakage is of crucial importance, since they allow to detect possible attacks to information assets (e.g., installation of malware), or can even compromise the security of PPDR personnel. HyIDS is an Hybrid IDS for Android and supporting the stringent security requirements of PPDR, by comprising agents that continuously monitor mobile device and periodically transmit the data to an analysis framework at the Command Control Center (CCC). The data collection retrieves resource usage metrics for each installed application such as CPU, memory usage, and incoming and outgoing network traffic. At the CCC, the HyIDS employs Machine Learning techniques to identify patterns that are consistent with malware signatures based on the data collected from the applications. The HyIDS's evaluation results demonstrate that the proposed solution has low impact on the mobile device in terms of battery consumption and CPU/memory usage.

Original languageEnglish
Title of host publicationProceedings of the IM 2017 - 2017 IFIP/IEEE International Symposium on Integrated Network and Service Management
EditorsProsper Chemouil, Paulo Simoes, Edmundo Madeira, Stefano Secci, Edmundo Monteiro, Luciano Paschoal Gaspary, Carlos Raniery P. dos Santos, Marinos Charalambides
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1034-1039
Number of pages6
ISBN (Electronic)9783901882890
DOIs
Publication statusPublished - 20 Jul 2017
Externally publishedYes
Event15th IFIP/IEEE International Symposium on Integrated Network and Service Management, IM 2017 - Lisbon, Portugal
Duration: 8 May 201712 May 2017

Publication series

NameProceedings of the IM 2017 - 2017 IFIP/IEEE International Symposium on Integrated Network and Service Management

Conference

Conference15th IFIP/IEEE International Symposium on Integrated Network and Service Management, IM 2017
Country/TerritoryPortugal
CityLisbon
Period8/05/1712/05/17

Fingerprint

Dive into the research topics of 'Towards a Hybrid Intrusion Detection System for Android-based PPDR terminals'. Together they form a unique fingerprint.

Cite this