Detecting Colluding Inter-App Communication in Mobile Environment

被引:5
|
作者
Casolare, Rosangela [1 ]
Martinelli, Fabio [2 ]
Mercaldo, Francesco [2 ,3 ]
Santone, Antonella [3 ]
机构
[1] Univ Molise, Dept Biosci & Terr, I-86090 Pesche, Italy
[2] Natl Res Council Italy, Inst Informat & Telemat, I-56124 Pisa, Italy
[3] Univ Molise, Dept Med & Hlth Sci Vincenzo Tiberio, I-86100 Campobasso, Italy
来源
APPLIED SCIENCES-BASEL | 2020年 / 10卷 / 23期
关键词
colluding; malware; model checking; formal methods; security; Android; mobile;
D O I
10.3390/app10238351
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
The increase in computing capabilities of mobile devices has, in the last few years, made possible a plethora of complex operations performed from smartphones and tablets end users, for instance, from a bank transfer to the full management of home automation. Clearly, in this context, the detection of malicious applications is a critical and challenging task, especially considering that the user is often totally unaware of the behavior of the applications installed on their device. In this paper, we propose a method to detect inter-app communication i.e., a colluding communication between different applications with data support to silently exfiltrate sensitive and private information. We based the proposed method on model checking, by representing Android applications in terms of automata and by proposing a set of logic properties to reduce the number of comparisons and a set of logic properties automatically generated for detecting colluding applications. We evaluated the proposed method on a set of 1092 Android applications, including different colluding attacks, by obtaining an accuracy of 1, showing the effectiveness of the proposed method.
引用
收藏
页码:1 / 23
页数:23
相关论文
共 50 条
  • [1] Identifying Mobile Inter-App Communication Risks
    Elish, Karim O.
    Cai, Haipeng
    Barton, Daniel
    Yao, Danfeng
    Ryder, Barbara G.
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2020, 19 (01) : 90 - 102
  • [2] Detecting Vulnerable Android Inter-App Communication in Dynamically Loaded Code
    Alhanahnah, Mohannad
    Yan, Qiben
    Bagheri, Hamid
    Zhou, Hao
    Tsutano, Yutaka
    Srisa-an, Witawas
    Luo, Xiapu
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 550 - 558
  • [3] Detecting Vulnerable Android Inter-App Communication in Dynamically Loaded Code
    Alhanahnah, Mohannad
    Yan, Qiben
    Bagheri, Hamid
    Zhou, Hao
    Tsutano, Yutaka
    Srisa-An, Witawas
    Luo, Xiapu
    Proceedings - IEEE INFOCOM, 2019, 2019-April : 550 - 558
  • [4] DINA: Detecting Hidden Android Inter-App Communication in Dynamic Loaded Code
    Alhanahnah, Mohannad
    Yan, Qiben
    Bagheri, Hamid
    Zhou, Hao
    Tsutano, Yutaka
    Srisa-an, Witawas
    Luo, Xiapu
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 2782 - 2797
  • [5] POSTER: Detecting Inter-App Information Leakage Paths
    Bhandari, Shweta
    Herbreteau, Frederic
    Laxmi, Vijay
    Zemmari, Akka
    Roop, Partha S.
    Gaur, Manoj Singh
    PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, : 908 - 910
  • [6] Prioritized Analysis of Inter-App Communication Risks
    Liu, Fang
    Cai, Haipeng
    Wang, Gang
    Yao, Danfeng
    Elish, Karim O.
    Ryder, Barbara G.
    PROCEEDINGS OF THE SEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY'17), 2017, : 159 - 161
  • [7] Inter-app Communication in Android: Developer Challenges
    Ahmad, Waqar
    Kaestner, Christian
    Sunshine, Joshua
    Aldrich, Jonathan
    13TH WORKING CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR 2016), 2016, : 177 - 188
  • [8] Android inter-app communication threats and detection techniques
    Bhandari, Shweta
    Ben Jaballah, Wafa
    Jain, Vineeta
    Laxmi, Vijay
    Zemmari, Akka
    Gaur, Manoj Singh
    Mosbah, Mohamed
    Conti, Mauro
    COMPUTERS & SECURITY, 2017, 70 : 392 - 421
  • [9] IacDroid: Preventing Inter-App Communication Capability Leaks in Android
    Zhang, Daojuan
    Wang, Rui
    Lin, Zimin
    Guo, Dianjie
    Cao, Xiaochun
    2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 443 - 449
  • [10] Detecting and Defending against Inter-App Permission Leaks in Android Apps
    He, Yi
    Li, Qi
    2016 IEEE 35TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2016,