SneakLeak: Detecting multipartite leakage paths in Android apps

被引:6
|
作者
Bhandari, Shweta [1 ]
Herbreteau, Frederic [2 ]
Laxmi, Vijay [1 ]
Zemmari, Akka [2 ]
Roop, Partha S. [3 ]
Gaur, Manoj Singh [1 ]
机构
[1] Malaviya Natl Inst Technol Jaipur, Dept Comp Sci & Engn, Jaipur, Rajasthan, India
[2] Univ Bordeaux, CNRS, LaBRI, F-33405 Talence, France
[3] Univ Auckland, Dept Elect & Comp Engn, Auckland, New Zealand
关键词
App Collusion; Multi-app Analysis; Verification; Model checking; Information Leakage; Permission Escalation;
D O I
10.1109/Trustcom/BigDataSE/ICESS.2017.249
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, a technique is proposed to address the threat emerging from multiple colluding Android applications (apps). Existing techniques have focused on single app analysis which may be defeated by scattering leakage-capable path segments across multiple apps. In such a scenario, individual app shall appear benign. Whereas, together with other conspiring apps, if present, can lead to information leakage. This threat is known as app collusion. Relay of private and sensitive information from one app to another is possible via multiple communication mechanisms provided by Android. In this paper, we present SneakLeak, a new model-checking based technique for detection of app collusion. The proposed method analyze multiple apps simultaneously. SneakLeak can identify any set of conspiring apps that might be involved in the collusion. To demonstrate the efficacy of our proposal, we experimented with Android apps exhibiting collusion through inter-app communication. The apps are taken from test dataset named DroidBench. Our experiments show that the technique can precisely detect the presence/absence of collusion among apps.
引用
收藏
页码:285 / 292
页数:8
相关论文
共 50 条
  • [31] Quantitave Dynamic Taint Analysis of Privacy Leakage in Android Arabic Apps
    Youssef, Ayman
    Shosha, Ahmed F.
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2017), 2017,
  • [32] Unmasking Privacy Leakage through Android Apps Obscured with Hidden Permissions
    Kotak, Pranav
    Bhandari, Shweta
    Zemmari, Akka
    Joshi, Jaykrishna
    2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [33] TraceDroid: Detecting Android Malware by Trace of Privacy Leakage
    Wu, Yueqing
    Fu, Hao
    Zhang, Guoming
    Zhao, Bin
    Xu, Minghui
    Zou, Yifei
    Feng, Xiaotao
    Hu, Pengfei
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS (WASA 2022), PT I, 2022, 13471 : 466 - 478
  • [34] SneakLeak+: Large-scale klepto apps analysis
    Bhandari, Shweta
    Herbreteau, Frederic
    Laxmi, Vijay
    Zemmari, Akka
    Gaur, Manoj Singh
    Roop, Partha S.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 109 : 593 - 603
  • [35] An Empirical Study of Code Deobfuscations on Detecting Obfuscated Android Piggybacked Apps
    Zhang, Yanxin
    Xiao, Guanping
    Zheng, Zheng
    Zhu, Tianqing
    Tsang, Ivor W.
    Sui, Yulei
    2020 27TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2020), 2020, : 41 - 50
  • [36] IccTA: Detecting Inter-Component Privacy Leaks in Android Apps
    Li, Li
    Bartel, Alexandre
    Bissyande, Tegawende F.
    Klein, Jacques
    Le Traon, Yves
    Arzt, Steven
    Rasthofer, Siegfried
    Bodden, Eric
    Octeau, Damien
    McDaniel, Patrick
    2015 IEEE/ACM 37TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, VOL 1, 2015, : 280 - 291
  • [37] Combining Multimodal DNN and SigPid technique for detecting Malicious Android Apps
    Vasu, Balaji
    Pari, Neelavathy
    2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 289 - 294
  • [38] Understanding and Detecting Fragmentation-Induced Compatibility Issues for Android Apps
    Wei, Lili
    Liu, Yepang
    Cheung, Shing-Chi
    Huang, Huaxun
    Lu, Xuan
    Liu, Xuanzhe
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2020, 46 (11) : 1176 - 1199
  • [39] Understanding and Detecting Evolution-Induced Compatibility Issues in Android Apps
    He, Dongjie
    Li, Lian
    Wang, Lei
    Zheng, Hengjie
    Li, Guangwei
    Xue, Jingling
    PROCEEDINGS OF THE 2018 33RD IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMTED SOFTWARE ENGINEERING (ASE' 18), 2018, : 167 - 177
  • [40] Rebooting Research on Detecting Repackaged Android Apps: Literature Review and Benchmark
    Li, Li
    Bissyande, Tegawende F.
    Klein, Jacques
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2021, 47 (04) : 676 - 693