作者
Karim O Elish, Haipeng Cai, Daniel Barton, Danfeng Yao, Barbara G Ryder
发表日期
2018/12/23
期刊
IEEE Transactions on Mobile Computing
卷号
19
期号
1
页码范围
90-102
出版商
IEEE
简介
Malware collusion is a technique utilized by attackers to evade standard detection. It is a new threat where two or more applications, appearing benign, communicate to perform a malicious task. Most proposed approaches aim at detecting stand-alone malicious applications. We point out the need for analyzing data flows across multiple Android apps, a problem referred to as end-to-end flow analysis. In this work, we present a flow analysis for app pairs that computes the risk level associated with their potential communications. Our approach statically analyzes the sensitivity and context of each inter-app flow based on inter-component communication (ICC) between communicating apps, and defines fine-grained security policies for inter-app ICC risk classification. We perform an empirical study on 7,251 apps from the Google Play store to identify the apps that communicate with each other via ICC channels. Our …
引用总数
20192020202120222023202411741362
学术搜索中的文章
KO Elish, H Cai, D Barton, D Yao, BG Ryder - IEEE Transactions on Mobile Computing, 2018