eddLeak: Enhancing Precision of Detecting Inter-app Data Leakage in Android Applications

被引:0
|
作者
Phan The Duy [1 ]
Van-Hau Pham [1 ]
Nguyen Tan Cam [2 ]
机构
[1] Vietnam Natl Univ, Univ Informat Technol, Informat Secur Lab, Ho Chi Minh City, Vietnam
[2] Hoa Sen Univ, Fac Sci & Technol, Ho Chi Minh City, Vietnam
关键词
android security analysis; inter-component communication; inter-application communication; sensitive information leakage; static analysis; inter-app leakage;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In recent years, mobile malware has grown to be significant types of behaviors, including stealing personal information of users, hijacking and surveilling user devices. Every year, it caused financial loss for infected enterprises, also more and more concerned about seriously secure data problems. Hence, many solutions have been proposed in order to detect malware leading to sensitive data leakage by analyzing mobile applications. Static analysis is a widely used technique for analyzing software, particularly in the security context, such as malware detection. Unfortunately, the static analysis technique often produces false alarms, which require significant manual effort to improve, such as DidFail tool. In this paper, we show how to analyze Android applications with static analysis to detect and identify which apps can be used to leak out sensitive information of users. We improve DidFail's architecture by implementing more modules and focus on the principles of Inter-Component Communication (ICC) between components in one or cross applications, then combining Android permission rules model to propose eddLeak approach, which enhance DidFail's precision of detecting inter-app leakage on Android applications and evaluate on customized application datasets.
引用
收藏
页码:674 / 679
页数:6
相关论文
共 50 条
  • [1] Detecting Android Inter-App Data Leakage via Compositional Concolic Walking
    Wu, Tianjun
    Yang, Yuexiang
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2019, 25 (04): : 755 - 766
  • [2] POSTER: Detecting Inter-App Information Leakage Paths
    Bhandari, Shweta
    Herbreteau, Frederic
    Laxmi, Vijay
    Zemmari, Akka
    Roop, Partha S.
    Gaur, Manoj Singh
    PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, : 908 - 910
  • [3] COVERT: Compositional Analysis of Android Inter-App Permission Leakage
    Bagheri, Hamid
    Sadeghi, Alireza
    Garcia, Joshua
    Malek, Sam
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2015, 41 (09) : 866 - 886
  • [4] Detecting and Defending against Inter-App Permission Leaks in Android Apps
    He, Yi
    Li, Qi
    2016 IEEE 35TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2016,
  • [5] Detecting Vulnerable Android Inter-App Communication in Dynamically Loaded Code
    Alhanahnah, Mohannad
    Yan, Qiben
    Bagheri, Hamid
    Zhou, Hao
    Tsutano, Yutaka
    Srisa-an, Witawas
    Luo, Xiapu
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 550 - 558
  • [6] Detecting Vulnerable Android Inter-App Communication in Dynamically Loaded Code
    Alhanahnah, Mohannad
    Yan, Qiben
    Bagheri, Hamid
    Zhou, Hao
    Tsutano, Yutaka
    Srisa-An, Witawas
    Luo, Xiapu
    Proceedings - IEEE INFOCOM, 2019, 2019-April : 550 - 558
  • [7] A SEALANT for Inter-App Security Holes in Android
    Lee, Youn Kyu
    Bang, Jae Young
    Safi, Gholamreza
    Shahbazian, Arman
    Zhao, Yixue
    Medvidovic, Nenad
    2017 IEEE/ACM 39TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE), 2017, : 312 - 323
  • [8] DINA: Detecting Hidden Android Inter-App Communication in Dynamic Loaded Code
    Alhanahnah, Mohannad
    Yan, Qiben
    Bagheri, Hamid
    Zhou, Hao
    Tsutano, Yutaka
    Srisa-an, Witawas
    Luo, Xiapu
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 2782 - 2797
  • [9] Inter-app Communication in Android: Developer Challenges
    Ahmad, Waqar
    Kaestner, Christian
    Sunshine, Joshua
    Aldrich, Jonathan
    13TH WORKING CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR 2016), 2016, : 177 - 188
  • [10] A model-based framework for inter-app Vulnerability analysis of Android applications
    Nirumand, Atefeh
    Zamani, Bahman
    Tork-Ladani, Behrouz
    Klein, Jacques
    Bissyande, Tegawende F.
    SOFTWARE-PRACTICE & EXPERIENCE, 2023, 53 (04): : 895 - 936