eddLeak: Enhancing Precision of Detecting Inter-app Data Leakage in Android Applications

被引:0
|
作者
Phan The Duy [1 ]
Van-Hau Pham [1 ]
Nguyen Tan Cam [2 ]
机构
[1] Vietnam Natl Univ, Univ Informat Technol, Informat Secur Lab, Ho Chi Minh City, Vietnam
[2] Hoa Sen Univ, Fac Sci & Technol, Ho Chi Minh City, Vietnam
来源
2017 IEEE 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN) | 2017年
关键词
android security analysis; inter-component communication; inter-application communication; sensitive information leakage; static analysis; inter-app leakage;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In recent years, mobile malware has grown to be significant types of behaviors, including stealing personal information of users, hijacking and surveilling user devices. Every year, it caused financial loss for infected enterprises, also more and more concerned about seriously secure data problems. Hence, many solutions have been proposed in order to detect malware leading to sensitive data leakage by analyzing mobile applications. Static analysis is a widely used technique for analyzing software, particularly in the security context, such as malware detection. Unfortunately, the static analysis technique often produces false alarms, which require significant manual effort to improve, such as DidFail tool. In this paper, we show how to analyze Android applications with static analysis to detect and identify which apps can be used to leak out sensitive information of users. We improve DidFail's architecture by implementing more modules and focus on the principles of Inter-Component Communication (ICC) between components in one or cross applications, then combining Android permission rules model to propose eddLeak approach, which enhance DidFail's precision of detecting inter-app leakage on Android applications and evaluate on customized application datasets.
引用
收藏
页码:674 / 679
页数:6
相关论文
共 15 条
  • [11] Collusive Data Leak and More: Large-scale Threat Analysis of Inter-app Communications
    Bosu, Amiangshu
    Liu, Fang
    Yao, Danfeng
    Wang, Gang
    PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, : 71 - 85
  • [12] Detecting Potential User-data Save & Export Losses due to Android App Termination
    Rahaman, Sydur
    Farooq, Umar
    Neamtiu, Iulian
    Zhao, Zhijia
    2023 IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATION OF SOFTWARE TEST, AST, 2023, : 152 - 162
  • [13] Sensitive data leakage detection in pre-installed applications of custom Android firmware
    Nguyen Tan Cam
    Van-Hau Pham
    Tuan Nguyen
    2017 18TH IEEE INTERNATIONAL CONFERENCE ON MOBILE DATA MANAGEMENT (IEEE MDM 2017), 2017, : 340 - 343
  • [14] Detect Sensitive Data Leakage via Inter-application on Android by Using Static Analysis and Dynamic Analysis
    Nguyen Tan Cam
    Van-Hau Pham
    Tuan Nguyen
    INFORMATION SCIENCE AND APPLICATIONS 2017, ICISA 2017, 2017, 424 : 298 - 305
  • [15] SIAT: A systematic inter-component communication real-time analysis technique for detecting data leak threats on Android
    Hu, Yupeng
    Kuang, Wenxin
    Zhe, Jin
    Li, Wenjia
    Li, Keqin
    Zhang, Jiliang
    Hu, Qiao
    JOURNAL OF COMPUTER SECURITY, 2024, 32 (03) : 291 - 317