Ghost Installer in the Shadow: Security Analysis of App Installation on Android

被引:5
|
作者
Lee, Yeonjoon [1 ]
Li, Tongxin [2 ]
Zhang, Nan [1 ]
Demetriou, Soteris [3 ]
Zha, Mingming [4 ]
Wang, XiaoFeng [1 ]
Chen, Kai [4 ]
Zhou, Xiaoyong [5 ]
Han, Xinhui [2 ]
Grace, Michael [5 ]
机构
[1] Indiana Univ, Bloomington, IN 47405 USA
[2] Peking Univ, Beijing, Peoples R China
[3] Univ Illinois, Champaign, IL USA
[4] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[5] Samsung Res Amer, Mountain View, CA USA
基金
美国国家科学基金会;
关键词
D O I
10.1109/DSN.2017.33
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Android allows developers to build apps with app installation functionality themselves with minimal restriction and support like any other functionalities. Given the critical importance of app installation, the security implications of the approach can be significant. This paper reports the first systematic study on this issue, focusing on the security guarantees of different steps of the App Installation Transaction (AIT). We demonstrate the serious consequences of leaving AIT development to individual developers: most installers (e.g., Amazon AppStore, DTIgnite, Baidu) are riddled with various security-critical loopholes, which can be exploited by attackers to silently install any apps, acquiring dangerous-level permissions or even unauthorized access to system resources. Surprisingly, vulnerabilities were found in all steps of AIT. The attacks we present, dubbed Ghost Installer Attack (GIA), are found to pose a realistic threat to Android ecosystem. Further, we developed both a user-app-level and a system-level defense that are innovative and practical.
引用
收藏
页码:403 / 414
页数:12
相关论文
共 50 条
  • [31] SEALANT: A Detection and Visualization Tool for Inter-app Security Vulnerabilities in Android
    Lee, Youn Kyu
    Yoodee, Peera
    Shahbazian, Arman
    Daye Nam
    Medvidovic, Nenad
    PROCEEDINGS OF THE 2017 32ND IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE'17), 2017, : 883 - 888
  • [33] Assessing the security of inter-app communications in android through reinforcement learning
    Romdhana, Andrea
    Merlo, Alessio
    Ceccato, Mariano
    Tonella, Paolo
    COMPUTERS & SECURITY, 2023, 131
  • [34] A Dynamic Taint Analysis Tool for Android App Forensics
    Xu, Zhen
    Shi, Chen
    Cheng, Chris Chao-Chun
    Gong, Neil Zhengqiang
    Guan, Yong
    2018 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2018), 2018, : 160 - 169
  • [35] An Android App for Spatial Acoustic Analysis as a Learning Tool
    DePue, Thomas H.
    Robistow, Benjamin
    Newman, Robert
    Mack, Kevin
    Banavar, Mahesh K.
    Yang, Tianqi
    Barry, Dana
    Curtis, Paul
    Spanias, Andreas
    Watkins, Whitni
    2016 IEEE FRONTIERS IN EDUCATION CONFERENCE (FIE), 2016,
  • [36] JICER: Simplifying Cooperative Android App Analysis Tasks
    Pauck, Felix
    Wehrheim, Heike
    IEEE 21ST INTERNATIONAL WORKING CONFERENCE ON SOURCE CODE ANALYSIS AND MANIPULATION (SCAM 2021), 2021, : 187 - 197
  • [37] Fault in your stars: An Analysis of Android App Reviews
    Aralikatte, Rahul
    Sridhara, Giriprasad
    Gantayat, Neelamadhav
    Mani, Senthil
    PROCEEDINGS OF THE ACM INDIA JOINT INTERNATIONAL CONFERENCE ON DATA SCIENCE AND MANAGEMENT OF DATA (CODS-COMAD'18), 2018, : 57 - 66
  • [38] AndroLyze: A Distributed Framework for Efficient Android App Analysis
    Baumgaertner, Lars
    Graubner, Pablo
    Schmidt, Nils
    Freisleben, Bernd
    2015 IEEE THIRD INTERNATIONAL CONFERENCE ON MOBILE SERVICES MS 2015, 2015, : 73 - 80
  • [39] FlowMine: Android App Analysis via Data Flow
    Sinha, Lovely
    Bhandari, Shweta
    Faruki, Parvez
    Gaur, Manoj Singh
    Laxmi, Vijay
    Conti, Mauro
    2016 13TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2016,
  • [40] SafeCandy: System for security, analysis and validation in Android
    Londono, Sebastian
    Camilo Urcuqui, Christian
    Navarro Cadavid, Andres
    Fuentes Amaya, Manuel
    Gomez, Johan
    SISTEMAS & TELEMATICA, 2015, 13 (35): : 89 - 102