{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,13]],"date-time":"2026-02-13T19:43:24Z","timestamp":1771011804970,"version":"3.50.1"},"reference-count":29,"publisher":"MDPI AG","issue":"14","license":[{"start":{"date-parts":[[2019,7,11]],"date-time":"2019-07-11T00:00:00Z","timestamp":1562803200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61572165"],"award-info":[{"award-number":["61572165"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61702150"],"award-info":[{"award-number":["61702150"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61803135"],"award-info":[{"award-number":["61803135"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Public Research Project of Zhejiang Province","award":["LGG19F020015"],"award-info":[{"award-number":["LGG19F020015"]}]},{"name":"Key Research and Development Plan Project of Zhejiang Province","award":["2017C01065"],"award-info":[{"award-number":["2017C01065"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Mobile payment apps have been widely-adopted, which brings great convenience to people\u2019s lives. However, at the same time, user\u2019s privacy is possibly eavesdropped and maliciously exploited by attackers. In this paper, we consider a possible way for an attacker to monitor people\u2019s privacy on a mobile payment app, where the attacker aims to identify the user\u2019s financial transactions at the trading stage via analyzing the encrypted network traffic. To achieve this goal, a hierarchical identification system is established, which can acquire users\u2019 privacy information in three different manners. First, it identifies the mobile payment app from traffic data, then classifies specific actions on the mobile payment app, and finally, detects the detailed steps within the action. In our proposed system, we extract reliable features from the collected traffic data generated on the mobile payment app, then use a series of well-performing ensemble learning strategies to deal with three identification tasks. Compared with prior works, the experimental results demonstrate that our proposed hierarchical identification system performs better.<\/jats:p>","DOI":"10.3390\/s19143052","type":"journal-article","created":{"date-parts":[[2019,7,11]],"date-time":"2019-07-11T11:28:28Z","timestamp":1562844508000},"page":"3052","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["Hierarchical Identifier: Application to User Privacy Eavesdropping on Mobile Payment App"],"prefix":"10.3390","volume":"19","author":[{"given":"Yaru","family":"Wang","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Hangzhou Dianzi University, Hangzhou 310018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ning","family":"Zheng","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Hangzhou Dianzi University, Hangzhou 310018, China"},{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ming","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tong","family":"Qiao","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiang","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Feipeng","family":"Yan","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Hangzhou Dianzi University, Hangzhou 310018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jian","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Hangzhou Dianzi University, Hangzhou 310018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,7,11]]},"reference":[{"key":"ref_1","unstructured":"Moore, D., Keys, K., Koga, R., and Lagache, E. (2019, July 10). CoralReef software suite as a tool for system and network administrators. Available online: http:\/\/www.caida.org\/publications\/papers\/2001\/CoralApps\/CoralApps.pdf."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1109\/MNET.2003.1248656","article-title":"Packet-level traffic measurements from the Sprint IP backbone","volume":"17","author":"Fraleigh","year":"2003","journal-title":"IEEE Netw."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Sen, S., Spatscheck, O., and Wang, D. (2004, January 17\u201320). Accurate, scalable in-network identification of p2p traffic using application signatures. Proceedings of the 13th International Conference on World Wide Web, New York, NY, USA.","DOI":"10.1145\/988672.988742"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Moore, A.W., and Papagiannaki, K. (2005). Toward the accurate identification of network applications. International Workshop on Passive and Active Network Measurement, Springer.","DOI":"10.1007\/978-3-540-31966-5_4"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Sun, G.L., Xue, Y., Dong, Y., Wang, D., and Li, C. (2010, January 6\u201310). An novel hybrid method for effectively classifying encrypted traffic. Proceedings of the 2010 IEEE Global Telecommunications Conference GLOBECOM 2010, Miami, FL, USA.","DOI":"10.1109\/GLOCOM.2010.5683649"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Arndt, D.J., and Zincir-Heywood, A.N. (2011, January 11\u201315). A comparison of three machine learning techniques for encrypted network traffic analysis. Proceedings of the 2011 IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA), Paris, France.","DOI":"10.1109\/CISDA.2011.5945941"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Alshammari, R., and Zincir-Heywood, A.N. (2007, January 7\u201310). A flow based approach for ssh traffic detection. Proceedings of the 2007 IEEE International Conference on Systems, Man and Cybernetics, Montreal, QC, Canada.","DOI":"10.1109\/ICSMC.2007.4414006"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Kumano, Y., Ata, S., Nakamura, N., Nakahira, Y., and Oka, I. (2014, January 3\u20136). Towards real-time processing for application identification of encrypted traffic. Proceedings of the 2014 International Conference on Computing, Networking and Communications (ICNC), Honolulu, HI, USA.","DOI":"10.1109\/ICCNC.2014.6785319"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Taylor, V.F., Spolaor, R., Conti, M., and Martinovic, I. (2016, January 7\u20138). Appscanner: Automatic fingerprinting of smartphone apps from encrypted network traffic. Proceedings of the 2016 IEEE European Symposium on Security and Privacy (EuroS&P), San Sebastian, Spain.","DOI":"10.1109\/EuroSP.2016.40"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"2851","DOI":"10.1109\/TMC.2016.2516020","article-title":"Service usage classification with encrypted internet traffic in mobile messaging apps","volume":"15","author":"Fu","year":"2016","journal-title":"IEEE Trans. Mob. Comput."},{"key":"ref_11","first-page":"254","article-title":"Encryption is Not Enough: Inferring User Activities on KakaoTalk with Traffic Analysis","volume":"Volume 9503","author":"Kim","year":"2016","journal-title":"Information Security Applications, Proceedings of the International Workshop on Information Security Applications, Jeju Island, Korea, 20\u201322 August 2015"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1109\/TIFS.2017.2737970","article-title":"Robust smartphone app identification via encrypted network traffic analysis","volume":"13","author":"Taylor","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"2658","DOI":"10.1109\/COMST.2018.2843533","article-title":"The dark side (-channel) of mobile devices: A survey on network traffic analysis","volume":"20","author":"Conti","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Yan, F., Xu, M., Qiao, T., Wu, T., Yang, X., Zheng, N., and Choo, K.K.R. (2018, January 1\u20133). Identifying WeChat Red Packets and Fund Transfers Via Analyzing Encrypted Network Traffic. Proceedings of the 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/12th IEEE International Conference on Big Data Science And Engineering (TrustCom\/BigDataSE), New York, NY, USA.","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00198"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Le, A., Varmarken, J., Langhoff, S., Shuba, A., Gjoka, M., and Markopoulou, A. (2015, January 17). AntMonitor: A system for monitoring from mobile devices. Proceedings of the 2015 ACM SIGCOMM Workshop on Crowdsourcing and Crowdsharing of Big (Internet) Data, London, UK.","DOI":"10.1145\/2787394.2787396"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Dai, S., Tongaonkar, A., Wang, X., Nucci, A., and Song, D. (2013, January 14\u201319). Networkprofiler: Towards automatic fingerprinting of android apps. Proceedings of the 2013 Proceedings IEEE INFOCOM, Turin, Italy.","DOI":"10.1109\/INFCOM.2013.6566868"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"St\u00f6ber, T., Frank, M., Schmitt, J., and Martinovic, I. (2013, January 17\u201319). Who do you sync you are?: smartphone fingerprinting via application behaviour. Proceedings of the Sixth ACM Conference on Security and Privacy in Wireless and Mobile Networks, Budapest, Hungary.","DOI":"10.1145\/2462096.2462099"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Wang, Q., Yahyavi, A., Kemme, B., and He, W. (2015, January 28\u201330). I know what you did on your smartphone: Inferring app usage over encrypted data traffic. Proceedings of the 2015 IEEE Conference on Communications and Network Security (CNS), Florence, Italy.","DOI":"10.1109\/CNS.2015.7346855"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1145\/2677046.2677048","article-title":"Traffic analysis of encrypted messaging services: Apple imessage and beyond","volume":"44","author":"Coull","year":"2014","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Conti, M., Mancini, L.V., Spolaor, R., and Verde, N.V. (2015, January 2\u20134). Can\u2019t you hear me knocking: Identification of user actions on android apps via traffic analysis. Proceedings of the 5th ACM Conference on Data and Application Security and Privacy, San Antonio, TX, USA.","DOI":"10.1145\/2699026.2699119"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/TIFS.2015.2478741","article-title":"Analyzing android encrypted network traffic to identify user actions","volume":"11","author":"Conti","year":"2016","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Park, K., and Kim, H. (2015). Encryption Is Not Enough: Inferring user activities on KakaoTalk with traffic analysis. International Workshop on Information Security Applications, Springer.","DOI":"10.1007\/978-3-319-31875-2_21"},{"key":"ref_23","unstructured":"Saltaformaggio, B., Choi, H., Johnson, K., Kwon, Y., Zhang, Q., Zhang, X., Xu, D., and Qian, J. (2016, January 8\u20139). Eavesdropping on fine-grained user activities within smartphone apps over encrypted network traffic. Proceedings of the 10th {USENIX} Workshop on Offensive Technologies ({WOOT} 16), Austin, TX, USA."},{"key":"ref_24","first-page":"18","article-title":"Classification and regression by randomForest","volume":"2","author":"Liaw","year":"2002","journal-title":"R News"},{"key":"ref_25","unstructured":"Ho, T.K. (1995, January 14\u201315). Random decision forests. Proceedings of the 3rd International Conference on Document Analysis and Recognition, Montreal, QC, Canada."},{"key":"ref_26","unstructured":"Rojas, R. (2019, July 10). AdaBoost and the super bowl of classifiers a tutorial introduction to adaptive boosting. Available online: http:\/\/www.inf.fu-berlin.de\/inst\/ag-ki\/rojas_home\/documents\/tutorials\/adaboost4.pdf."},{"key":"ref_27","unstructured":"Mason, L., Baxter, J., Bartlett, P.L., and Frean, M.R. (2000). Boosting algorithms as gradient descent. Advances in Neural Information Processing Systems, The MIT Press."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Chen, T., and Guestrin, C. (2016, January 13\u201317). Xgboost: A scalable tree boosting system. Proceedings of the 22nd ACM Sigkdd International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939785"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"M\u00fcller, M. (2007). Information Retrieval for Music and Motion, Springer.","DOI":"10.1007\/978-3-540-74048-3"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/14\/3052\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T13:04:28Z","timestamp":1760187868000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/14\/3052"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,7,11]]},"references-count":29,"journal-issue":{"issue":"14","published-online":{"date-parts":[[2019,7]]}},"alternative-id":["s19143052"],"URL":"https:\/\/doi.org\/10.3390\/s19143052","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,7,11]]}}}