DocumentCode :
168982
Title :
Android - On-device detection of SMS catchers and sniffers
Author :
Teufl, Peter ; Zefferer, Thomas ; Woergoetter, Christoph ; Oprisnik, Alexander ; Hein, Daniel
Author_Institution :
Inst. for Appl. Inf. Process. & Commun., Graz Univ. of Technol., Graz, Austria
fYear :
2014
fDate :
11-14 May 2014
Firstpage :
1
Lastpage :
8
Abstract :
With 6.1 trillion text messages sent in 2010 alone, short message service (SMS) is still one of the most popular mobile communication services. Due to its continuing popularity, SMS technology is nowadays used in various fields of application. This also includes security-sensitive fields such as e-banking, or e-government. In these fields, SMS technology is for instance employed to authorize financial transactions or the creation of qualified electronic signatures. Modern smartphone platforms such as Google Android provide application developers with the means to include SMS functionality. This can be beneficial in most cases but also facilitates the implementation of malware that is able to send and receive SMS messages unnoticed by the legitimate end user. In this context, SMS sniffers and SMS catchers have recently attracted attention. This kind of malware intercepts incoming SMS messages either to spy on security-sensitive data transmitted via SMS or to receive SMS-based malware control commands. For security-sensitive SMS-based applications, SMS catchers pose a serious threat. A recent attack on SMS-based e-banking systems has employed SMS catchers on smartphones to steal 36.000.000 Euro from corporate and private bank accounts in Europe. Unfortunately, security software for smartphones is still in the fledging stages and current solutions are not able to reliably detect SMS catchers. To overcome this problem, we introduce different methods to detect SMS sniffers and SMS catchers on smartphones. We discuss benefits and limitations of the proposed methods and show how these methods can be assembled to a comprehensive detection workflow for SMS-based malware. By providing means to detect SMS catchers and sniffers on smartphones, our work contributes to the security of current and future SMS-based applications.
Keywords :
digital signatures; electronic messaging; invasive software; smart phones; Google Android; SMS catchers; SMS functionality; SMS messages; SMS sniffers; SMS technology; SMS-based e-banking system; SMS-based malware control command; comprehensive detection workflow; continuing popularity; corporate bank account; e-government; financial transactions; mobile communication services; on-device detection; private bank account; qualified electronic signature; security software; security-sensitive SMS-based application; security-sensitive data; security-sensitive field; short message service; smartphone platform; smartphones; text messages; Androids; Humanoid robots; Malware; Online banking; Receivers; Smart phones;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy and Security in Mobile Systems (PRISMS), 2014 International Conference on
Conference_Location :
Aalborg
Print_ISBN :
978-1-4799-4630-3
Type :
conf
DOI :
10.1109/PRISMS.2014.6970601
Filename :
6970601
Link To Document :
بازگشت