<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en"><front><journal-meta><journal-id journal-id-type="publisher-id">Discrete and Continuous Models and Applied Computational Science</journal-id><journal-title-group><journal-title xml:lang="en">Discrete and Continuous Models and Applied Computational Science</journal-title><trans-title-group xml:lang="ru"><trans-title>Discrete and Continuous Models and Applied Computational Science</trans-title></trans-title-group></journal-title-group><issn publication-format="print">2658-4670</issn><issn publication-format="electronic">2658-7149</issn><publisher><publisher-name xml:lang="en">Peoples' Friendship University of Russia named after Patrice Lumumba (RUDN University)</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">51921</article-id><article-id pub-id-type="doi">10.22363/2658-4670-2026-34-2-187-200</article-id><article-id pub-id-type="edn">JDISSJ</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>Computer Science</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>Информатика и вычислительная техника</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">Development of the malicious traffic detection system for mobile applications security</article-title><trans-title-group xml:lang="ru"><trans-title>Обеспечение безопасности мобильных систем с помощью приложений для обнаружения вредоносного трафика</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0001-2418-3556</contrib-id><name-alternatives><name xml:lang="en"><surname>Khalemskii</surname><given-names>Nikita D.</given-names></name><name xml:lang="ru"><surname>Халемский</surname><given-names>Н. Д.</given-names></name></name-alternatives><bio xml:lang="en"><p>Master Student of Telecommunications R\&amp;D Institute National Research University Higher School of Economics (HSE University)</p></bio><email>ndkhalemskiy@edu.hse.ru</email><xref ref-type="aff" rid="aff1"/></contrib><contrib contrib-type="author"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-1373-4014</contrib-id><contrib-id contrib-id-type="scopus">57192573001</contrib-id><name-alternatives><name xml:lang="en"><surname>Beschastnyi</surname><given-names>Vitalii A.</given-names></name><name xml:lang="ru"><surname>Бесчастный</surname><given-names>В. А.</given-names></name></name-alternatives><bio xml:lang="en"><p>Candidate of Physical and Mathematical Sciences, assistant professor of Department of Probability Theory and Cybersecurity, RUDN University; Senior Researcher of Telecommunications R&amp;D Institute National Research University Higher School of Economics (HSE University)</p></bio><email>beschastnyy-va@rudn.ru</email><xref ref-type="aff" rid="aff1"/><xref ref-type="aff" rid="aff2"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="en">HSE University</institution></aff><aff><institution xml:lang="ru">Национальный исследовательский университет «Высшая школа экономики»</institution></aff></aff-alternatives><aff-alternatives id="aff2"><aff><institution xml:lang="en">RUDN University</institution></aff><aff><institution xml:lang="ru">Российский университет дружбы народов</institution></aff></aff-alternatives><pub-date date-type="pub" iso-8601-date="2026-08-15" publication-format="electronic"><day>15</day><month>08</month><year>2026</year></pub-date><volume>34</volume><issue>2</issue><issue-title xml:lang="en">VOL 34, NO2 (2026)</issue-title><issue-title xml:lang="ru">ТОМ 34, №2 (2026)</issue-title><fpage>187</fpage><lpage>200</lpage><history><date date-type="received" iso-8601-date="2026-08-20"><day>20</day><month>08</month><year>2026</year></date></history><permissions><copyright-statement xml:lang="en">Copyright ©; 2026, Khalemskii N.D., Beschastnyi V.A.</copyright-statement><copyright-statement xml:lang="ru">Copyright ©; 2026, Халемский Н.Д., Бесчастный В.А.</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="en">Khalemskii N.D., Beschastnyi V.A.</copyright-holder><copyright-holder xml:lang="ru">Халемский Н.Д., Бесчастный В.А.</copyright-holder><ali:free_to_read xmlns:ali="http://www.niso.org/schemas/ali/1.0/"/><license><ali:license_ref xmlns:ali="http://www.niso.org/schemas/ali/1.0/">https://creativecommons.org/licenses/by-nc/4.0</ali:license_ref></license></permissions><self-uri xlink:href="https://journals.rudn.ru/miph/article/view/51921">https://journals.rudn.ru/miph/article/view/51921</self-uri><abstract xml:lang="en"><p>Background: The rapid increase in cyberattacks targeting infrastructure, enterprises, and individual users through mobile devices has created an urgent need for effective intrusion detection systems. Traditional signature-based methods are inadequate against zero-day vulnerabilities and advanced persistent threats, prompting the exploration of machine learning approaches for network traffic analysis. Purpose: This study aims to develop and evaluate a privacy-preserving, locally operating Android application for real-time malicious traffic detection using machine learning models, addressing the limitations of cloud-dependent security architectures that compromise user privacy and availability. Methods: We implemented five machine learning algorithms - XGBoost, LightGBM, Random Forest, Decision Tree, and Logistic Regression - trained on the Network Traffic Android Malware dataset. The models were exported to the ONNX format for local deployment on Android devices. Performance was evaluated using accuracy, precision, recall, AUC score, training time, and model size metrics, with multi-criteria decision analysis (MCDA) applied for comprehensive comparison. Results: Gradient boosting algorithms demonstrated superior performance, with LightGBM achieving the highest MCDA score (0.9759), fastest training time (0.32 s), and smallest model size (0.28 MB), while XGBoost attained the highest AUC-score (0.9627). Both models significantly outperformed Random Forest (MCDA: 0.7532), Decision Tree (0.6743), and Logistic Regression (0.1407). Conclusions: LightGBM provides an optimal balance between detection accuracy and mobile resource constraints, making it suitable for on-device deployment. The proposed architecture demonstrates that fully local, ML-based traffic analysis is feasible without compromising detection quality, offering a privacy-centric alternative to server-dependent solutions for next-generation mobile intrusion detection systems.</p></abstract><trans-abstract xml:lang="ru"><p>Актуальность: Стремительный рост кибератак, направленных на объекты инфраструктуры, предприятия и индивидуальных пользователей через мобильные устройства, обусловливает потребность в эффективных системах обнаружения вторжений. Традиционные сигнатурные методы не позволяют противостоять уязвимостям нулевого дня и сложным постоянным угрозам (Advanced Persistent Threats, APT), что стимулирует исследование подходов машинного обучения для анализа сетевого трафика. Цель: Исследование направлено на разработку и оценку локально функционирующего Android-приложения, обеспечивающего конфиденциальность данных и выполняющего обнаружение вредоносного трафика в реальном времени на основе моделей машинного обучения. Решение позволяет преодолевать ограничения облачных архитектур безопасности, которые ставят под угрозу приватность пользователей и доступность сервисов. Методы: Были проанализированы пять моделей машинного обучения - XGBoost, LightGBM, случайный лес, дерево решений и логистическая регрессия, - обученных на наборе данных Network Traffic Android Malware. Модели были экспортированы в формат ONNX для локального развёртывания на устройствах под управлением Android. Оценка производительности осуществлялась по показателям точности (accuracy), полноты (recall), площади под ROC-кривой (AUC), времени обучения и размеру модели; для комплексного сравнения применялся многокритериальный анализ решений. Результаты: Алгоритмы градиентного бустинга продемонстрировали превосходные результаты: LightGBM достиг наивысшей оценки (0,9759), минимального времени обучения (0,32 с) и наименьшего размера модели (0,28 МБ), тогда как XGBoost показал максимальную площадь под ROC-кривой (0,9627). Обе модели значительно превзошли случайный лес (0,7532), дерево решений (0,6743) и логистическую регрессию (0,1407). Выводы: LightGBM показала оптимальный баланс между точностью обнаружения и ограниченными ресурсами мобильных устройств, что делает её пригодной для внутриплатформенного развёртывания. Предложенная архитектура демонстрирует, что полностью локальный анализ трафика на основе машинного обучения осуществим без потери качества обнаружения и представляет собой конфиденциально-ориентированную альтернативу серверно-зависимым решениям для систем обнаружения вторжений в мобильных сетях следующего поколения.</p></trans-abstract><kwd-group xml:lang="en"><kwd>signature-based detection</kwd><kwd>machine learning</kwd><kwd>anomaly detection</kwd><kwd>mobile traffic monitoring</kwd><kwd>real-time data processing</kwd><kwd>cybersecurity</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>сигнатурные методы обнаружения</kwd><kwd>машинное обучение</kwd><kwd>обнаружение аномалий</kwd><kwd>мониторинг трафика</kwd><kwd>обработка даных в реальном времени</kwd><kwd>кибербезопасность</kwd></kwd-group><funding-group><award-group><funding-source><institution-wrap><institution xml:lang="en">The reported study was funded by RSF, projects no. 23-79-10084, https://rscf.ru/en/project/23-79-10084/.</institution></institution-wrap></funding-source></award-group></funding-group></article-meta><fn-group/></front><body></body><back><ref-list><ref id="B1"><label>1.</label><mixed-citation>G. B. H. Vaibhav, M. Bafna, G. Sumathi, and R. Gopi, “Android Malware Detection using Federated Learning,” in Proceedings of the 2025 IEEE International Conference on Artificial Intelligence and Signal Processing (AISP), Tirunelveli, India, 2025. DOI: 10.1109/AISP64076.2025.10689155</mixed-citation></ref><ref id="B2"><label>2.</label><mixed-citation>T. Chen and C. Guestrin, “XGBoost: A Scalable Tree Boosting System,” in Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, ACM, 2016,pp. 785-794. DOI: 10.1145/2939672.2939785</mixed-citation></ref><ref id="B3"><label>3.</label><mixed-citation>G. Ke, Q. Meng, T. Finley, T. Wang, W. Chen, W. Ma, Q. Ye, and T.-Y. Liu, “LightGBM: A Highly Efficient Gradient Boosting Decision Tree,” in Advances in Neural Information Processing Systems 30 (NIPS 2017), Curran Associates, 2017, pp. 3146-3154.</mixed-citation></ref><ref id="B4"><label>4.</label><mixed-citation>L. Breiman, “Random Forests,” Machine Learning, vol. 45, no. 1, pp. 5-32, 2001. DOI: 10.1023/A:1010933404324</mixed-citation></ref><ref id="B5"><label>5.</label><mixed-citation>S.-l. developers. “Decision Trees.” Scikit-learn documentation, scikit-learn, Accessed: Apr. 24, 2025. [Online]. Available: https://scikit-learn.org/stable/modules/tree.html</mixed-citation></ref><ref id="B6"><label>6.</label><mixed-citation>S.-l. developers. “Logistic Regression.” Scikit-learn documentation, scikit-learn, Accessed: Apr. 24, 2025. [Online]. Available: https://scikit-learn.org/stable/modules/linear_model.html#logistic-regression</mixed-citation></ref><ref id="B7"><label>7.</label><mixed-citation>C. Urcuqui, Network Traffic Android Malware, version 1.0, 2019.</mixed-citation></ref><ref id="B8"><label>8.</label><mixed-citation>O. Community, ONNX: Open Neural Network Exchange, version 1.16, Open standard for machine learning interoperability, 2024.</mixed-citation></ref><ref id="B9"><label>9.</label><mixed-citation>A. Botvinko and K. Samouylov, “Evaluation of the firewall influence on the session initiation by the SIP multimedia protocol,” Discrete and Continuous Models and Applied Computational Science, vol. 29, pp. 221-229, Sep. 2021. DOI: 10.22363/2658-4670-2021-29-3-221-229</mixed-citation></ref><ref id="B10"><label>10.</label><mixed-citation>A. S. Baklashov and D. S. Kulyabov, “Statistical and density-based clustering techniques in the context of anomaly detection in network systems: A comparative analysis,” Discrete and Continuous Models and Applied Computational Science, vol. 33, no. 1, pp. 27-45, 2025.</mixed-citation></ref><ref id="B11"><label>11.</label><mixed-citation>S. Zhou, H. Zeng, Y. Lu, Y. Chen, J. Liu, and J. Su, “A Lightweight Embedded Intelligent Threat Detection System Using TSANet on Android Platforms,” in Proceedings of the 2025 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), Raipur, India, 2025. DOI: 10.1109/ANTS63432.2025.10689230</mixed-citation></ref><ref id="B12"><label>12.</label><mixed-citation>E. Faranda, PCAPdroid - No-root network monitor, GitHub, Version 1.7.1, 2024.</mixed-citation></ref><ref id="B13"><label>13.</label><mixed-citation>T. W. Team, Wireshark - Network Protocol Analyzer, version 4.4.2, 2024.</mixed-citation></ref><ref id="B14"><label>14.</label><mixed-citation>O. Corporation. “Java Native Interface Specification.” Java SE 8 Documentation, Oracle, Accessed: Apr. 24, 2025. [Online]. Available: https://docs.oracle.com/javase/8/docs/technotes/guides/jni/</mixed-citation></ref><ref id="B15"><label>15.</label><mixed-citation>D. Cao, S. Wang, Q. Li, Z. Cheny, Q. Yan, L. Peng, and B. Yang, “DroidCollector: A High Performance Framework for High Quality Android Traffic Collection,” in 2016 IEEE Trustcom/BigDataSE/ISPA, IEEE, 2016, pp. 1753-1758. DOI: 10.1109/TrustCom.2016.0270</mixed-citation></ref><ref id="B16"><label>16.</label><mixed-citation>J. Tang, S. Zhou, T. Peng, X. Yan, X. Hu, and W. Tian, “DTDroid: Adversarial Packed Android Malware Detection Based on Traffic and Dynamic Behavioral,” IEEE Internet of Things Journal, vol. 12, no. 3, pp. 2646-2658, 2025. DOI: 10.1109/JIOT.2024.3477442</mixed-citation></ref><ref id="B17"><label>17.</label><mixed-citation>C. C. U. López, J. S. D. Villarreal, A. F. P. Belalcazar, A. N. Cadavid, and J. G. D. Cely, “Features to Detect Android Malware,” in 2018 IEEE Colombian Conference on Communications and Computing (COLCOM), IEEE, 2018, pp. 1-6. DOI: 10.1109/ColComCon.2018.8466715</mixed-citation></ref><ref id="B18"><label>18.</label><mixed-citation>S. Anand, B. Mitra, S. Dey, A. Rao, R. Dhar, and J. Vaidya, “MALITE: Lightweight Malware Detection and Classification for Constrained Devices,” IEEE Transactions on Emerging Topics in Computing, vol. 13, no. 3, pp. 1099-1112, 2025. DOI: 10.1109/TETC.2025.3566370</mixed-citation></ref><ref id="B19"><label>19.</label><mixed-citation>E. K. Zavadskas, Z. Turskis, and J. Antuchevičienė, “Multi-Criteria Decision Making (MCDM) Methods and Concepts,” Encyclopedia, vol. 3, no. 1, p. 6, 2023. DOI: 10.3390/encyclopedia3010006</mixed-citation></ref><ref id="B20"><label>20.</label><mixed-citation>O. Y. Mohammed and I. A. Saleh, “Prediction Wireless Network Traffic Evaluation Potential Based on Ensemble Algorithms,” in Proceedings of the 2025 IEEE 22nd International Multi-Conference on Systems, Signals &amp; Devices (SSD), Monastir, Tunisia, 2025, pp. 914-921. DOI: 10.1109/SSD63744.2025.10689473</mixed-citation></ref><ref id="B21"><label>21.</label><mixed-citation>Y. K. Sharma, D. S. Tomar, R. K. Pateriya, and S. Solanki, “GNSTAM: Integrating Graph Networks With Spatial and Temporal Signature Analysis for Enhanced Android Malware Detection,” IEEE Access, vol. 13, pp. 81 326-81 346, 2025. DOI: 10.1109/ACCESS.2025.3582741</mixed-citation></ref></ref-list></back></article>
