{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T03:53:22Z","timestamp":1760241202608,"version":"build-2065373602"},"reference-count":20,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2019,12,26]],"date-time":"2019-12-26T00:00:00Z","timestamp":1577318400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"the Cyberspace Security Major Program in the National Key Research and Development Plan of China","award":["2016YFB0800201"],"award-info":[{"award-number":["2016YFB0800201"]}]},{"name":"the Natural Science Foundation of China","award":["61572165","61702150","61803135"],"award-info":[{"award-number":["61572165","61702150","61803135"]}]},{"name":"the State Key Program of Zhejiang Province Natural Science Foundation of China","award":["LZ15F020003"],"award-info":[{"award-number":["LZ15F020003"]}]},{"name":"the Key Research and Development Plan Project of Zhejiang Province","award":["2017C01065"],"award-info":[{"award-number":["2017C01065"]}]},{"name":"the Public Research Project of Zhejiang Province","award":["LGG19F020015."],"award-info":[{"award-number":["LGG19F020015."]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Attackers can eavesdrop and exploit user privacy by classifying traffic into different types of in-app service usage to identify user actions. WeChat is the largest social messaging platform, which is a popular application in China. When WeChat is shut down, it is unable to generate traffic; that is, traditional traffic. However, the traffic still can be generated by system. How to identify the message types within WeChat with traffic generated by a system instead of traditional traffic becomes a new challenge. To deal with this challenge, we designed a system to identify and analyze the traffic of the Apple Push Notification service (APNs) to identify the message types of WeChat. In detail, we designed a system to identify and analyze the traffic of the APNs. First, the system clusters the traffic based on the session and divides it into multiple bursts. Then, it extracts the features of each burst and sends these features to the learning-based classifier to extract APNs\u2019s traffic from the background traffic. Finally, it uses a hash-based lookup table method to analyze message types from APNs traffic. Extensive evaluation results show that we can accurately identify the six message types of APN and WeChat. In addition, we propose two coping strategies for the method proposed in this article.<\/jats:p>","DOI":"10.3390\/info11010018","type":"journal-article","created":{"date-parts":[[2019,12,27]],"date-time":"2019-12-27T05:37:08Z","timestamp":1577425028000},"page":"18","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Identifying WeChat Message Types without Using Traditional Traffic"],"prefix":"10.3390","volume":"11","author":[{"given":"Qiang","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ming","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ning","family":"Zheng","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"},{"name":"School of Computer Science and Technology, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tong","family":"Qiao","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yaru","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,12,26]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Wang, Y., Zheng, N., Xu, M., Qiao, T., Zhang, Q., Yan, F., and Xu, J. (2019). Hierarchical Identifier: Application to User Privacy Eavesdropping on Mobile Payment App. Sensors, 19.","DOI":"10.3390\/s19143052"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Wang, Q., Yahyavi, A., Kemme, B., and He, W. (2015, January 28\u201330). I know what you did on your smartphone: Inferring app usage over encrypted data traffic. Proceedings of the 2015 IEEE Conference on Communications and Network Security (CNS), Florence, Italy.","DOI":"10.1109\/CNS.2015.7346855"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Park, K., and Kim, H. (2015, January 20\u201322). Encryption Is Not Enough: Inferring user activities on KakaoTalk with traffic analysis. Proceedings of the International Workshop on Information Security Applications, Jeju Island, Korea.","DOI":"10.1007\/978-3-319-31875-2_21"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/TIFS.2015.2478741","article-title":"Analyzing android encrypted network traffic to identify user actions","volume":"11","author":"Conti","year":"2016","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"2851","DOI":"10.1109\/TMC.2016.2516020","article-title":"Service Usage Classification with Encrypted Internet Traffic in Mobile Messaging Apps","volume":"15","author":"Fu","year":"2016","journal-title":"IEEE Trans. Mob. Comput."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Shafiq, M., Yu, X., and Laghari, A.A. (2016, January 12\u201314). WeChat Text Messages Service Flow Traffic Classification Using Machine Learning Technique. Proceedings of the IEEE International Conference on IEEE International Conference on High-performance Computing & Communications, IEEE International Conference on Smart City, Sydney, NSW, Australia.","DOI":"10.1109\/HPCC-SmartCity-DSS.2016.0019"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1145\/2677046.2677048","article-title":"Traffic analysis of encrypted messaging services: Apple imessage and beyond","volume":"44","author":"Coull","year":"2014","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"2658","DOI":"10.1109\/COMST.2018.2843533","article-title":"The dark side (-channel) of mobile devices: A survey on network traffic analysis","volume":"20","author":"Conti","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_9","unstructured":"Guo, W., and Liu, H. (2013, January 16\u201318). The analysis of push technology based on iphone operating system. Proceedings of the 2013 2nd International Conference on Measurement, Information and Control, Harbin, China."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Wang, Y., Ke, W., and Tao, X. (2016). A feature selection method for large-scale network traffic classification based on spark. Information, 7.","DOI":"10.3390\/info7010006"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Sultan, K., Ali, H., Ahmad, A., and Zhang, Z. (2019). Call Details Record Analysis: A Spatiotemporal Exploration toward Mobile Traffic Classification and Optimization. Information, 10.","DOI":"10.3390\/info10060192"},{"key":"ref_12","unstructured":"Gusg\u00e5rd, O. (2019, December 25). Application Development for the Apple Watch. Available online: https:\/\/www.theseus.fi\/bitstream\/handle\/10024\/147350\/Gusgard_Thesis.pdf?sequence=1."},{"key":"ref_13","first-page":"117","article-title":"Designing the multimedia push framework for mobile applications","volume":"32","author":"Lee","year":"2011","journal-title":"Int. J. Adv. Sci. Technol."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Br\u00fcstel, J., and Preuss, T. (2012, January 4\u20136). A universal push service for mobile devices. Proceedings of the 2012 Sixth International Conference on Complex, Intelligent, and Software Intensive Systems, Palermo, Italy.","DOI":"10.1109\/CISIS.2012.105"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"St\u00f6ber, T., Frank, M., Schmitt, J., and Martinovic, I. (2013, January 17\u201319). Who do you sync you are? Smartphone fingerprinting via application behaviour. Proceedings of the Sixth ACM Conference on Security and Privacy in Wireless and Mobile Networks, New York, NY, USA.","DOI":"10.1145\/2462096.2462099"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Yan, F., Xu, M., Qiao, T., Wu, T., Yang, X., Zheng, N., and Choo, K.K.R. (2018, January 1\u20133). Identifying WeChat Red Packets and Fund Transfers Via Analyzing Encrypted Network Traffic. Proceedings of the 2018 17th IEEE International Conference On Trust, Security And Privacy in Computing And Communications\/12th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE), New York, NY, USA.","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00198"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"743","DOI":"10.1109\/TIFS.2018.2866025","article-title":"OTPaaS\u2014One time password as a service","volume":"14","author":"Erdem","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_18","first-page":"708","article-title":"Two birds with one stone: Two-factor authentication with security beyond conventional bound","volume":"15","author":"Wang","year":"2016","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"916","DOI":"10.1109\/JSYST.2016.2585681","article-title":"On the challenges in designing identity-based privacy-preserving authentication schemes for mobile devices","volume":"12","author":"Wang","year":"2016","journal-title":"IEEE Syst. J."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"e3900","DOI":"10.1002\/dac.3900","article-title":"User centric three-factor authentication protocol for cloud-assisted wearable devices","volume":"32","author":"Jiang","year":"2019","journal-title":"Int. J. Commun. Syst."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/11\/1\/18\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T13:45:49Z","timestamp":1760190349000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/11\/1\/18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12,26]]},"references-count":20,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2020,1]]}},"alternative-id":["info11010018"],"URL":"https:\/\/doi.org\/10.3390\/info11010018","relation":{},"ISSN":["2078-2489"],"issn-type":[{"type":"electronic","value":"2078-2489"}],"subject":[],"published":{"date-parts":[[2019,12,26]]}}}