eddLeak: Enhancing Precision of Detecting Inter-app Data Leakage in Android Applications

被引:0
|
作者
Phan The Duy [1 ]
Van-Hau Pham [1 ]
Nguyen Tan Cam [2 ]
机构
[1] Vietnam Natl Univ, Univ Informat Technol, Informat Secur Lab, Ho Chi Minh City, Vietnam
[2] Hoa Sen Univ, Fac Sci & Technol, Ho Chi Minh City, Vietnam
关键词
android security analysis; inter-component communication; inter-application communication; sensitive information leakage; static analysis; inter-app leakage;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In recent years, mobile malware has grown to be significant types of behaviors, including stealing personal information of users, hijacking and surveilling user devices. Every year, it caused financial loss for infected enterprises, also more and more concerned about seriously secure data problems. Hence, many solutions have been proposed in order to detect malware leading to sensitive data leakage by analyzing mobile applications. Static analysis is a widely used technique for analyzing software, particularly in the security context, such as malware detection. Unfortunately, the static analysis technique often produces false alarms, which require significant manual effort to improve, such as DidFail tool. In this paper, we show how to analyze Android applications with static analysis to detect and identify which apps can be used to leak out sensitive information of users. We improve DidFail's architecture by implementing more modules and focus on the principles of Inter-Component Communication (ICC) between components in one or cross applications, then combining Android permission rules model to propose eddLeak approach, which enhance DidFail's precision of detecting inter-app leakage on Android applications and evaluate on customized application datasets.
引用
收藏
页码:674 / 679
页数:6
相关论文
共 50 条
  • [41] The Dangers of Rooting: Data Leakage Detection in Android Applications
    Casati, Luca
    Visconti, Andrea
    MOBILE INFORMATION SYSTEMS, 2018, 2018
  • [42] An Analysis on Sensitive Data Passive Leakage in Android Applications
    Yang, Tianchang
    Cui, Haoliang
    Niu, Shaozhang
    Zhang, Peng
    2015 IEEE 16TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT), 2015, : 125 - 131
  • [43] Detecting Data Leakage from Databases on Android Apps with Concept Drift
    Kul, Gokhan
    Upadhyaya, Shambhu
    Chandola, Varun
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 905 - 913
  • [44] Android Collusion: Detecting Malicious Applications Inter-Communication through SharedPreferences
    Casolare, Rosangela
    Martinelli, Fabio
    Mercaldo, Francesco
    Santone, Antonella
    INFORMATION, 2020, 11 (06)
  • [45] Detecting Third-Party Libraries in Android Applications with High Precision and Recall
    Zhang, Yuan
    Dai, Jiarun
    Zhang, Xiaohan
    Huang, Sirong
    Yang, Zhemin
    Yang, Min
    Chen, Hao
    2018 25TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ANALYSIS, EVOLUTION AND REENGINEERING (SANER 2018), 2018, : 141 - 152
  • [46] Data Leakage Between C/S Communication: A Case Study on Android Music App
    Li, Huanhuan
    Luo, Qian
    Zhang, Shubin
    Zhang, Haibin
    Liu, Jiajia
    2017 9TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS AND SIGNAL PROCESSING (WCSP), 2017,
  • [47] Automatically Detecting Malicious Sensitive Data Usage in Android Applications
    Yan, Hongbing
    Xiong, Yan
    Huang, Wenchao
    Huang, Jianmeng
    Meng, Zhaoyi
    2018 4TH INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING AND COMMUNICATIONS (BIGCOM 2018), 2018, : 102 - 107
  • [48] Prevention of Data Leakage due to Implicit Information Flows in Android Applications
    Inayoshi, Hiroki
    Kakei, Shohei
    Takimoto, Eiji
    Mouri, Koichi
    Saito, Shoichi
    2019 14TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS 2019), 2019, : 103 - 110
  • [49] Exposing Android social applications: linking data leakage to privacy policies
    Krych, Daniel E.
    McDaniel, Patrick
    Journal of Cyber Security Technology, 2021, 5 (3-4) : 139 - 190
  • [50] Detecting Potential User-data Save & Export Losses due to Android App Termination
    Rahaman, Sydur
    Farooq, Umar
    Neamtiu, Iulian
    Zhao, Zhijia
    2023 IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATION OF SOFTWARE TEST, AST, 2023, : 152 - 162