Collusive Data Leak and More: Large-scale Threat Analysis of Inter-app Communications

被引:81
|
作者
Bosu, Amiangshu [1 ]
Liu, Fang [2 ]
Yao, Danfeng [2 ]
Wang, Gang [2 ]
机构
[1] Southern Illinois Univ, Dept Comp Sci, Carbondale, IL 62901 USA
[2] Virginia Tech, Dept Comp Sci, Blacksburg, VA USA
来源
PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17) | 2017年
关键词
Android; Security; Collusion; Inter-component communication; Inter-app communication; Privilege escalation; Intent;
D O I
10.1145/3052973.3053004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Inter-Component Communication (ICC) provides a message passing mechanism for data exchange between Android applications. It has been long believed that inter-app ICCs can be abused by malware writers to launch collusion attacks using two or more apps. However, because of the complexity of performing pairwise program analysis on apps, the scale of existing analyses is too small (e.g., up to several hundred) to produce concrete security evidence. In this paper, we report our findings in the first large-scale detection of collusive and vulnerable apps, based on inter-app ICC data flows among 110,150 real-world apps. Our system design aims to balance the accuracy of static ICC resolution/data-flow analysis and run-time scalability. This large-scale analysis provides real-world evidence and deep insights on various types of inter-app ICC abuse. Besides the empirical findings, we make several technical contributions, including a new open source ICC resolution tool with improved accuracy over the state-of-the-art, and a large database of inter-app ICCs and their attributes.
引用
收藏
页码:71 / 85
页数:15
相关论文
共 50 条
  • [21] An Epidemiology-inspired Large-scale Analysis of Android App Accessibility
    Ross, Anne Spencer
    Zhang, Xiaoyi
    Fogarty, James
    Wobbrock, Jacob O.
    ACM TRANSACTIONS ON ACCESSIBLE COMPUTING, 2020, 13 (01)
  • [22] Design and Analysis of Mobile App for Large-Scale Cyber-Argumentation
    Althuniyan, Najla
    Sirrianni, Joseph W.
    Rahman, Md Mahfuzer
    Liu, Xiaoqing ''Frank''
    2020 SECOND INTERNATIONAL CONFERENCE ON TRANSDISCIPLINARY AI (TRANSAI 2020), 2020, : 50 - 58
  • [23] Large-Scale Mobile Fitness App Usage Analysis for Smart Health
    Chen, Xinlei
    Zhu, Zheqi
    Chen, Min
    Li, Yong
    IEEE COMMUNICATIONS MAGAZINE, 2018, 56 (04) : 46 - 52
  • [24] Teaching Programming to Novices: A Large-scale Analysis of App Inventor Projects
    Alves, Nathalia da Cruz
    von Wangenheim, Christiane Gresse
    Rossa Hauck, Jean Carlo
    2020 XV CONFERENCIA LATINOAMERICANA DE TECNOLOGIAS DE APRENDIZAJE (LACLO), 2020,
  • [25] Deep learning for the large-scale cancer data analysis
    Tsuji, Shingo
    Aburatani, Hiroyuki
    CANCER RESEARCH, 2015, 75 (22)
  • [26] CytoGPS: A large-scale karyotype analysis of CML data
    Abrams, Zachary B.
    Li, Suli
    Zhang, Lin
    Coombes, Caitlin E.
    Payne, Philip R. O.
    Heerema, Nyla A.
    Abruzzo, Lynne, V
    Coombes, Kevin R.
    CANCER GENETICS, 2020, 248 : 34 - 38
  • [27] Large-scale data analysis using the Wigner function
    Earnshaw, R. A.
    Lei, C.
    Li, J.
    Mugassabi, S.
    Vourdas, A.
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2012, 391 (07) : 2401 - 2407
  • [28] Large-Scale Data Analysis Using Heuristic Methods
    Dzemyda, Gintautas
    Sakalauskas, Leonidas
    INFORMATICA, 2011, 22 (01) : 1 - 10
  • [29] Computational solutions to large-scale data management and analysis
    Schadt, Eric E.
    Linderman, Michael D.
    Sorenson, Jon
    Lee, Lawrence
    Nolan, Garry P.
    NATURE REVIEWS GENETICS, 2010, 11 (09) : 647 - 657
  • [30] Rational choice theory and large-scale data analysis
    Weakliem, DL
    CONTEMPORARY SOCIOLOGY-A JOURNAL OF REVIEWS, 1999, 28 (02) : 246 - 247