Detection and Deterrence from Data Collecting Applications in Android

被引:0
作者
Tiwari, Pradeep Kumar [1 ]
Velayutham, T. [1 ]
机构
[1] Bharat Elect Ltd, Cent Res Lab, Bengaluru, India
来源
2016 FOURTH INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (PDGC) | 2016年
关键词
android; Data Collection; privacy; data leakage; smali; Covert Communication;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As Android User's and its application market is growing; android applications tend to collect user's data for various purposes; for advertisement agencies, for better user experiences and to learn about user's behavior on internet. However, it raises concern about privacy of an individual being compromised. We propose a methodology, to make android applications deterrent to data leakage as well as detect covert communications in them. We have used reverse engineering approaches to identify sources and sinks of the data leakage as well as covert communication, if any. We tested our methodology over a set a 57 highly popular applications from PlayStore and found that nearly 40% are covertly collecting user's data and nearly 60% are making questionable connections to undeclared servers. However, after modification of application we did not find much difference in user experiences. We also did a case study of data logging application, DroidWatch by Justin Grover.
引用
收藏
页码:326 / 331
页数:6
相关论文
共 17 条
[1]  
[Anonymous], 2013, IBM RATIONAL APPSCAN
[2]  
[Anonymous], 2013, FORTIFY 360 SOURCE C
[3]  
[Anonymous], 2011, USENIX SEC S
[4]  
[Anonymous], 2012, TRUST TRUSTWORTHY CO
[5]  
[Anonymous], 2012, SPSM 12 P WORKSHOP S
[6]  
Arzt S., 2013, SUSI TOOL FULLY AUT
[7]  
Arzt S, 2014, ACM SIGPLAN NOTICES, V49, P259, DOI [10.1145/2594291.2594299, 10.1145/2666356.2594299]
[8]  
Batyuk L., 2011, 2011 6th International Conference on Malicious and Unwanted Software, P66, DOI 10.1109/MALWARE.2011.6112328
[9]  
Chin E, 2011, Proceedings of the 9th International Conference on Mobile Systems, Applications, and Services, MobiSys '11, New York, NY, USA, P239, DOI DOI 10.1145/1999995.2000018
[10]  
Enck William., 2010, Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI), P393