Detection of app collusion potential using logic programming

Detection of app collusion potential using logic programming
复制标题

使用逻辑编程检测应用程序共谋的可能性

DOI:
10.1016/j.jnca.2017.12.008
复制
发表时间:
2018
影响因子:
8.7
通讯作者:
Blasco J
Blasco J
中科院分区:
计算机科学2区
文献类型:
--
作者:
Blasco J

文献摘要

参考文献

被引文献

相似文献

移动的设备构成了特定的安全风险,因为它们保存了个人详细信息(帐户、位置、联系人、照片),并且具有可能被窃听的能力(相机/麦克风、无线连接)。Android操作系统设计有许多内置的安全功能,例如应用程序沙箱和基于权限的访问控制。不幸的是,这些限制可以在用户没有注意到的情况下被合谋的应用绕过,这些应用的组合权限允许它们执行任何应用都无法单独执行的攻击。虽然应用合谋的可能性在2011年首次被警告,但由于缺乏合适的检测方法和工具,目前还不清楚合谋是否被恶意软件使用。本文描述了我们是如何在野外发现第一个共谋的。我们还提出了一个策略,用于检测共谋和它的实现在Prolog中,使我们能够做出这一发现。我们的检测策略是基于简明的定义共谋和ASR(发送-接收)签名的概念。该方法得到统计证据的支持。我们的方法可扩展,适用于纳入专业的恶意软件检测系统:我们将其应用于一组在野外收集的50,000多个应用程序。我们的工具以及检测到的恶意软件的代码样本是可用的。
Mobile devices pose a particular security risk because they hold personal details (accounts, locations, contacts, photos) and have capabilities potentially exploitable for eavesdropping (cameras/microphone, wireless connections). The Android operating system is designed with a number of built-in security features such as application sandboxing and permission-based access control. Unfortunately, these restrictions can be bypassed, without the user noticing, by colluding apps whose combined permissions allow them to carry out attacks that neither app is able to execute by itself.While the possibility of app collusion was first warned in 2011, it has been unclear if collusion is used by malware in the wild due to a lack of suitable detection methods and tools. This paper describes how we found the first collusion in the wild. We also present a strategy for detecting collusions and its implementation in Prolog that allowed us to make this discovery.Our detection strategy is grounded in concise definitions of collusion and the concept of ASR (Access-Send-Receive) signatures. The methodology is supported by statistical evidence. Our approach scales and is applicable to inclusion into professional malware detection systems: we applied it to a set of more than 50,000 apps collected in the wild. Code samples of our tool as well as of the detected malware are available.
DOI: 10.1145/2897845.2897904
发表时间: 2016-05
期刊: Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security
影响因子: --
作者:
Yiming Jing;Gail-Joon Ahn;Adam Doupé;J. Yi
通讯作者: Yiming Jing;Gail-Joon Ahn;Adam Doupé;J. Yi
适用于 Android 的基于 SELinux 的意图管理器
DOI: 10.1109/cns.2015.7346916
发表时间: 2015
期刊: 2015 IEEE Conference on Communications and Network Security (CNS)
影响因子: --
作者:
S. Mutti;Enrico Bacis;S. Paraboschi
通讯作者: S. Paraboschi