iABC: Towards a hybrid framework for analyzing and classifying behaviour of iOS applications using static and dynamic analysis

被引:2
作者
Bhatt, Arpita Jadhav [1 ]
Gupta, Chetna [1 ]
Mittal, Sangeeta [1 ]
机构
[1] Jaypee Inst Informat Technol, Noida 201301, India
关键词
iOS applications; Reverse engineering; Machine learning; Static analysis; Dynamic analysis; Static risk score;
D O I
10.1016/j.jisa.2018.07.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Is this app safe to use? - A wrong decision can result in privacy breach in iOS devices. In this digital era users extensively use smart devices to store their personal and important information. To ease users' tasks, thousands of free or paid apps are available in app store. However, recent studies reveal startling facts about various attacks and data harvesting incidents through these apps, where personal data is put at risk. Through this paper, we propose a permission induced risk model-iOS Application analyzer and Behavior Classifier (iABC), for iOS devices to detect privacy violations arising due to granting permissions during installation of applications. It is a two-layer process comprising of static and dynamic analysis. It uses reverse engineering to extract permission variables from applications and computes a risk score for each application using ranking algorithms. The approach considers application's category as a key feature for detecting malicious applications while computing static risk score. Different machine learning classifiers were employed to evaluate 1,150 applications. The empirical results show that our proposed model gives detection rate of 97.04%. Furthermore, to assess privacy breaches by applications at run time, dynamic analysis on 50 applications has been performed to obtain dynamic risk scores of installed apps. (c) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:144 / 158
页数:15
相关论文
共 56 条
[1]  
Adhikari R., 2014, 25 AUSTR C INF SYST, P1
[2]  
[Anonymous], SMART INNOVATION SYS
[3]  
[Anonymous], 2012, TRUST TRUSTWORTHY CO
[4]  
Apple Inc, EVENTKIT APPL DEV DO
[5]  
Apple Inc, SPEECH APPL DEV DOC
[6]  
Apple Inc, AVFOUNDATION APPL DE
[7]  
Apple Inc, COR LOC APPL DEV DOC
[8]  
Apple Inc, AVCAPTUREDEVICE AVFO
[9]  
Apple Inc, SYSTEMCONFIGURATION
[10]  
Apple Inc, UIIMAGEPICKERCONTROL