Prioritized Analysis of Inter-App Communication Risks

被引:2
|
作者
Liu, Fang [1 ]
Cai, Haipeng [2 ]
Wang, Gang [1 ]
Yao, Danfeng [1 ]
Elish, Karim O. [3 ]
Ryder, Barbara G. [1 ]
机构
[1] Virginia Tech, Dept Comp Sci, Blacksburg, VA 24061 USA
[2] Washington State Univ, Sch Elect Engn & Comp Sci, Pullman, WA 99164 USA
[3] Florida Polytech Univ, Dept Comp Sci, Lakeland, FL USA
来源
PROCEEDINGS OF THE SEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY'17) | 2017年
关键词
D O I
10.1145/3029806.3029843
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Inter-Component Communication (ICC) enables useful interactions between mobile apps. However, misuse of ICC exposes users to serious threats such as intent hijacking/spoofing and app collusions, allowing malicious apps to access privileged user data via another app. Unfortunately, existing ICC analyses are largely incompetent in both accuracy and scale. This poster points out the need and technical challenges of prioritized analysis of inter-app ICC risks. We propose MR-Droid, a MapReduce-based computing framework for accurate and scalable inter-app ICC analysis in Android. MR-Droid extracts data-flow features between multiple communicating apps and the target apps to build a large-scale ICC graph. Our approach is to leverage the ICC graph to provide contexts for inter-app communications to produce precise alerts and prioritize risk assessments. This process requires large app-pair data, which is enabled by our MapReduce-based program analysis. Our initial extensive experiments on 11,996 apps from 24 app categories (13 million pairs) demonstrate the scalability of our approach.
引用
收藏
页码:159 / 161
页数:3
相关论文
共 50 条
  • [1] MR-Droid: A Scalable and Prioritized Analysis of Inter-App Communication Risks
    Liu, Fang
    Cai, Haipeng
    Wang, Gang
    Yao, Danfeng
    Elish, Karim O.
    Ryder, Barbara G.
    2017 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW 2017), 2017, : 189 - 198
  • [2] Identifying Mobile Inter-App Communication Risks
    Elish, Karim O.
    Cai, Haipeng
    Barton, Daniel
    Yao, Danfeng
    Ryder, Barbara G.
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2020, 19 (01) : 90 - 102
  • [3] Inter-app Communication in Android: Developer Challenges
    Ahmad, Waqar
    Kaestner, Christian
    Sunshine, Joshua
    Aldrich, Jonathan
    13TH WORKING CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR 2016), 2016, : 177 - 188
  • [4] Detecting Colluding Inter-App Communication in Mobile Environment
    Casolare, Rosangela
    Martinelli, Fabio
    Mercaldo, Francesco
    Santone, Antonella
    APPLIED SCIENCES-BASEL, 2020, 10 (23): : 1 - 23
  • [5] Behaviour analysis of inter-app communication using a lightweight monitoring app for malware detection
    Grace, M.
    Sughasiny, M.
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 210
  • [6] Android inter-app communication threats and detection techniques
    Bhandari, Shweta
    Ben Jaballah, Wafa
    Jain, Vineeta
    Laxmi, Vijay
    Zemmari, Akka
    Gaur, Manoj Singh
    Mosbah, Mohamed
    Conti, Mauro
    COMPUTERS & SECURITY, 2017, 70 : 392 - 421
  • [7] IacDroid: Preventing Inter-App Communication Capability Leaks in Android
    Zhang, Daojuan
    Wang, Rui
    Lin, Zimin
    Guo, Dianjie
    Cao, Xiaochun
    2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 443 - 449
  • [8] Detecting Vulnerable Android Inter-App Communication in Dynamically Loaded Code
    Alhanahnah, Mohannad
    Yan, Qiben
    Bagheri, Hamid
    Zhou, Hao
    Tsutano, Yutaka
    Srisa-an, Witawas
    Luo, Xiapu
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 550 - 558
  • [9] Picker Blinder: a framework for automatic injection of malicious inter-app communication
    Rosangela Casolare
    Stefano Fagnano
    Giacomo Iadarola
    Fabio Martinelli
    Francesco Mercaldo
    Antonella Santone
    Journal of Computer Virology and Hacking Techniques, 2024, 20 : 331 - 346
  • [10] Picker Blinder: a framework for automatic injection of malicious inter-app communication
    Casolare, Rosangela
    Fagnano, Stefano
    Iadarola, Giacomo
    Martinelli, Fabio
    Mercaldo, Francesco
    Santone, Antonella
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2024, 20 (02) : 331 - 346