AppJitsu: Investigating the Resiliency of Android Applications

AppJitsu: Investigating the Resiliency of Android Applications
复制标题

DOI:
10.1109/eurosp51992.2021.00038
复制
发表时间:
2021-09
期刊:
2021 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
Onur Zungur;Antonio Bianchi;G. Stringhini;Manuel Egele
Onur Zungur;Antonio Bianchi;G. Stringhini;Manuel Egele
中科院分区:
其他
文献类型:
--
作者:
Onur Zungur;Antonio Bianchi;G. Stringhini;Manuel Egele

文献摘要

被引文献

相似文献

Android 平台为移动设备用户提供了通过安装开发人员编写的应用程序来扩展其系统功能的机会。公司利用这种能力来接触客户并进行金融交易等业务运营。最终用户可以从 Google Play 获取自定义 Android 应用程序 (app),其中一些应用程序由于其处理的数据的性质而具有安全敏感性,例如金融类别的应用程序。尽管有使用各种自卫技术进行安全应用程序开发的建议和标准化指南,但这些方法的采用并不是强制性的,而是由开发人员自行决定。不幸的是,恶意行为者可以篡改应用程序运行时环境,然后利用篡改产生的攻击向量,例如在移动平台上以提升的权限执行外部代码。在本文中,我们提出了 AppJITSU,这是一个动态应用程序分析框架,用于评估安全关键应用程序的弹性。我们在针对特定攻击的敌对环境中测试了最流行的 455 个金融应用程序,以展示针对已知篡改方法的当前弹性状态。我们的结果表明,25.05% 的测试应用程序对任何常见的恶意方法或工具没有弹性,而只有 10.77% 的应用程序采用了所有防御方法。
The Android platform gives mobile device users the opportunity to extend the capabilities of their systems by installing developer-authored apps. Companies leverage this capability to reach their customers and conduct business operations such as financial transactions. End-users can obtain custom Android applications (apps) from the Google Play, some of which are security-sensitive due to the nature of the data that they handle, such as apps from the FINANCE category. Although there are recommendations and standardized guidelines for secure app development with various self-defense techniques, the adoption of such methods is not mandatory and is left to the discretion of developers. Unfortunately, malicious actors can tamper with the app runtime environment and then exploit the attack vectors which arise from the tampering, such as executing foreign code with elevated privileges on the mobile platform. In this paper, we present AppJITSU, a dynamic app analysis framework that evaluates the resiliency of security-critical apps. We exercise the most popular 455 financial apps in attack-specific hostile environments to demonstrate the current state of resiliency against known tampering methods. Our results indicate that 25.05% of the tested apps have no resiliency against any common hostile methods or tools, whereas only 10.77% employed all defensive methods.