DocumentCode :
2764127
Title :
Using static analysis for automatic assessment and mitigation of unwanted and malicious activities within Android applications
Author :
Batyuk, Leonid ; Herpich, Markus ; Camtepe, Seyit Ahmet ; Raddatz, Karsten ; Schmidt, Aubrey-Derrick ; Albayrak, Sahin
fYear :
2011
fDate :
18-19 Oct. 2011
Firstpage :
66
Lastpage :
72
Abstract :
In the last decade, smartphones have gained widespread usage. Since the advent of online application stores, hundreds of thousands of applications have become instantly available to millions of smart-phone users. Within the Android ecosystem, application security is governed by digital signatures and a list of coarse-grained permissions. However, this mechanism is not fine-grained enough to provide the user with a sufficient means of control of the applications´ activities. Abuse of highly sensible private information such as phone numbers without users´ notice is the result. We show that there is a high frequency of privacy leaks even among widely popular applications. Together with the fact that the majority of the users are not proficient in computer security, this presents a challenge to the engineers developing security solutions for the platform. Our contribution is twofold: first, we propose a service which is able to assess Android Market applications via static analysis and provide detailed, but readable reports to the user. Second, we describe a means to mitigate security and privacy threats by automated reverse-engineering and refactoring binary application packages according to the users´ security preferences.
Keywords :
data privacy; digital signatures; mobile computing; operating systems (computers); software maintenance; user interfaces; Android Market application; application security; binary application package refactoring; coarse-grained permission; digital signature; privacy threat mitigation; reverse-engineering package; security threat mitigation; smart phone; static analysis; user security preference; Androids; Detectors; Humanoid robots; Privacy; Security; Smart phones; Software;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Malicious and Unwanted Software (MALWARE), 2011 6th International Conference on
Conference_Location :
Fajardo
Print_ISBN :
978-1-4673-0031-5
Type :
conf
DOI :
10.1109/MALWARE.2011.6112328
Filename :
6112328
Link To Document :
بازگشت