DocumentCode
2764127
Title
Using static analysis for automatic assessment and mitigation of unwanted and malicious activities within Android applications
Author
Batyuk, Leonid ; Herpich, Markus ; Camtepe, Seyit Ahmet ; Raddatz, Karsten ; Schmidt, Aubrey-Derrick ; Albayrak, Sahin
fYear
2011
fDate
18-19 Oct. 2011
Firstpage
66
Lastpage
72
Abstract
In the last decade, smartphones have gained widespread usage. Since the advent of online application stores, hundreds of thousands of applications have become instantly available to millions of smart-phone users. Within the Android ecosystem, application security is governed by digital signatures and a list of coarse-grained permissions. However, this mechanism is not fine-grained enough to provide the user with a sufficient means of control of the applications´ activities. Abuse of highly sensible private information such as phone numbers without users´ notice is the result. We show that there is a high frequency of privacy leaks even among widely popular applications. Together with the fact that the majority of the users are not proficient in computer security, this presents a challenge to the engineers developing security solutions for the platform. Our contribution is twofold: first, we propose a service which is able to assess Android Market applications via static analysis and provide detailed, but readable reports to the user. Second, we describe a means to mitigate security and privacy threats by automated reverse-engineering and refactoring binary application packages according to the users´ security preferences.
Keywords
data privacy; digital signatures; mobile computing; operating systems (computers); software maintenance; user interfaces; Android Market application; application security; binary application package refactoring; coarse-grained permission; digital signature; privacy threat mitigation; reverse-engineering package; security threat mitigation; smart phone; static analysis; user security preference; Androids; Detectors; Humanoid robots; Privacy; Security; Smart phones; Software;
fLanguage
English
Publisher
ieee
Conference_Titel
Malicious and Unwanted Software (MALWARE), 2011 6th International Conference on
Conference_Location
Fajardo
Print_ISBN
978-1-4673-0031-5
Type
conf
DOI
10.1109/MALWARE.2011.6112328
Filename
6112328
Link To Document