App Collusion Detection (ACID)
应用程序合谋检测 (ACID)
基本信息
- 批准号:EP/L022699/1
- 负责人:
- 金额:$ 22.29万
- 依托单位:
- 依托单位国家:英国
- 项目类别:Research Grant
- 财政年份:2014
- 资助国家:英国
- 起止时间:2014 至 无数据
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Malware has been a major problem in desktop computing for decades. With the recent trend towards mobile computing, malware is moving rapidly to smartphone apps. Our business partner McAfee alone collected 17,000 Android malware samples in the most recent quarter, double the rate of the previous year. Criminals are clearly motivated by the opportunity - about one billion smartphones will be sold in 2013, predominantly Android, with more than 10 billion apps downloaded to date. Smartphones pose a particular security risk because they hold personal details (accounts, locations, contacts, photos) and have potential capabilities for eavesdropping (with cameras/microphone, wireless connections). By design, Android is "open" in its flexibility to download apps from different sources. Its security depends on restricting apps by combining digital signatures, sandboxing, and permissions.Unfortunately, these restrictions can be bypassed, without the user noticing, by colluding apps whose combined permissions allow them to carry out attacks that neither app can accomplish by itself. A basic example of collusion consists of one app permitted to access personal data, which passes the data to a second app allowed to transmit data over the network. While collusion is not a widespread threat today, it opens an avenue to circumvent Android permission restrictions that could be easily exploited by criminals to become a serious threat in the near future.The UK Cyber Security Strategy notes that UK industry, as well as the public, needs to have confidence in a safe cyber space. Emerging privacy threats to smartphones are particularly timely to address considering the current controversies about US government data collection and monitoring of private communications. Sensitive data leakage is the main security risk posed by colluding apps, and the proposed project will help maintain users' confidence in smartphone privacy. Currently almost all academic and industry efforts are focusing on detection of single malicious apps. Almost no attention has been given to colluding apps. The threat has been demonstrated only recently. The threat of colluding apps is challenging to detect because of the myriad and possibly stealthy ways in which apps might communicate and collude. Existing antivirus products are not designed to detect collusion. Preliminary research in the literature has not found any reliable means to detect collusion. This project directly addresses the aims of the BACCHUS call by building an important collaboration between McAfee and academic experts in network security, intrusion detection, and formal methods to develop innovative methods for collusion detection. Our industry partner McAfee is a global leading security company with extensive facilities for monitoring, collecting, and analyzing smartphone threats. This project aims to develop novel theoretical and practical methods to detect apps suspected of collusion and perform formal safety checking. The resulting methods will be deployed and tested by the industry partner, McAfee Labs, in their global Threat Intelligence System. If successful, the research project will help to proactively defend smart phones against the emerging threat of colluding apps. McAfee products are some of the most popular with the consumers in the UK, providing day-to-day guarding against PC and mobile threats.Success in this project would mean a rare opportunity for the cyber security community to stay ahead of an emerging threat instead of reacting to a threat already prevalent.
几十年来,恶意软件一直是桌面计算的主要问题。随着最近的移动的计算趋势,恶意软件正在迅速转移到智能手机应用程序。仅我们的业务合作伙伴McAfee就在最近一个季度收集了17,000个Android恶意软件样本,是去年的两倍。犯罪分子显然是受到了这个机会的激励--2013年将售出约10亿部智能手机,其中主要是Android,迄今为止下载的应用程序超过100亿个。智能手机带来了特别的安全风险,因为它们保存了个人详细信息(帐户,位置,联系人,照片),并具有潜在的窃听能力(通过摄像头/麦克风,无线连接)。通过设计,Android是“开放的”,可以灵活地从不同的来源下载应用程序。它的安全性依赖于通过结合数字签名、沙箱和权限来限制应用程序。不幸的是,这些限制可以在用户没有注意到的情况下被合谋的应用程序绕过,这些应用程序的组合权限允许它们执行任何应用程序都无法单独完成的攻击。合谋的一个基本示例包括一个允许访问个人数据的应用程序,该应用程序将数据传递给允许通过网络传输数据的第二个应用程序。虽然共谋目前还不是一个普遍的威胁,但它为规避Android权限限制开辟了一条途径,这些限制可能很容易被犯罪分子利用,在不久的将来成为一个严重的威胁。英国网络安全战略指出,英国工业界和公众都需要对安全的网络空间有信心。考虑到目前有关美国政府数据收集和私人通信监控的争议,智能手机面临的新隐私威胁尤其需要及时解决。敏感数据泄露是串通应用程序带来的主要安全风险,拟议中的项目将有助于维护用户对智能手机隐私的信心。目前,几乎所有的学术和行业努力都集中在检测单个恶意应用程序上。几乎没有人关注串通应用程序。这一威胁最近才得到证实。串通应用程序的威胁是具有挑战性的检测,因为无数的,可能是隐形的方式,应用程序可能沟通和串通。现有的防病毒产品并不是设计用来检测共谋的。文献中的初步研究没有发现任何可靠的手段来检测共谋。该项目通过在McAfee与网络安全、入侵检测和正式方法领域的学术专家之间建立重要合作关系,直接实现了BACCHUS呼吁的目标,以开发用于共谋检测的创新方法。我们的行业合作伙伴McAfee是一家全球领先的安全公司,拥有广泛的监控、收集和分析智能手机威胁的设施。该项目旨在开发新的理论和实践方法,以检测涉嫌共谋的应用程序并执行正式的安全检查。由此产生的方法将由行业合作伙伴McAfee Labs在其全球威胁情报系统中进行部署和测试。如果成功,该研究项目将有助于主动保护智能手机免受共谋应用程序的威胁。McAfee产品是英国最受消费者欢迎的产品之一,可提供日常防护,以防范PC和移动的威胁。该项目的成功将意味着网络安全社区有难得的机会领先于新兴威胁,而不是对已经普遍存在的威胁做出反应。
项目成果
期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
A Review of Significance of Energy-Consumption Anomaly in Malware Detection in Mobile Devices
移动设备恶意软件检测中能耗异常意义的综述
- DOI:10.22619/ijcsa.2016.1001010
- 发表时间:2016
- 期刊:
- 影响因子:0
- 作者:Qadri J
- 通讯作者:Qadri J
Data Analytics and Decision Support for Cybersecurity
网络安全的数据分析和决策支持
- DOI:
- 发表时间:2017
- 期刊:
- 影响因子:0
- 作者:Irina Mariuca Asavoae
- 通讯作者:Irina Mariuca Asavoae
Detection of app collusion potential using logic programming
使用逻辑编程检测应用程序共谋的可能性
- DOI:10.1016/j.jnca.2017.12.008
- 发表时间:2018
- 期刊:
- 影响因子:8.7
- 作者:Blasco J
- 通讯作者:Blasco J
Automated generation of colluding apps for experimental research
自动生成用于实验研究的合谋应用程序
- DOI:10.1007/s11416-017-0296-4
- 发表时间:2017
- 期刊:
- 影响因子:1.5
- 作者:Blasco J
- 通讯作者:Blasco J
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Thomas Chen其他文献
Localization Lengths and Boltzmann Limit for the Anderson Model at Small Disorders in Dimension 3
3 维小无序情况下安德森模型的定位长度和玻尔兹曼极限
- DOI:
- 发表时间:
2003 - 期刊:
- 影响因子:0
- 作者:
Thomas Chen - 通讯作者:
Thomas Chen
Boltzmann limit and quasifreeness for a homogeneous Fermion gas in a random medium
随机介质中均质费米子气体的玻尔兹曼极限和准自由度
- DOI:
- 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Thomas Chen;Itaru Sasaki - 通讯作者:
Itaru Sasaki
Enhanced binding for N-particle system interacting with a scalar bose field I
N 粒子系统与标量玻色场 I 相互作用的增强结合
- DOI:
- 发表时间:
2006 - 期刊:
- 影响因子:0
- 作者:
Thomas Chen;Itaru Sasaki;佐々木 格;佐々木 格;廣島 文生 - 通讯作者:
廣島 文生
Interferon‐Gamma (IFN‐γ) and Interleukin‐6 (IL‐6) in Peritoneal Fluid and Macrophage‐Conditioned Media of Women With Endometriosis
子宫内膜异位症女性腹腔液和巨噬细胞条件培养基中的干扰素-γ (IFN-γ) 和白细胞介素-6 (IL-6)
- DOI:
- 发表时间:
1994 - 期刊:
- 影响因子:3.6
- 作者:
J. Keenan;Thomas Chen;N. Chadwell;D. Torry;M. Caudle - 通讯作者:
M. Caudle
Critical manifolds and stability in Hamiltonian systems with non-holonomic constraints
具有非完整约束的哈密顿系统的临界流形和稳定性
- DOI:
10.1016/j.geomphys.2003.08.004 - 发表时间:
2003 - 期刊:
- 影响因子:1.5
- 作者:
Thomas Chen - 通讯作者:
Thomas Chen
Thomas Chen的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Thomas Chen', 18)}}的其他基金
Mathematical Analysis of Dispersion and Transport in Quantum Dynamics
量子动力学中色散和输运的数学分析
- 批准号:
2009800 - 财政年份:2020
- 资助金额:
$ 22.29万 - 项目类别:
Continuing Grant
Texas Analysis and Mathematical Physics Symposium 2017
2017年德州分析与数学物理研讨会
- 批准号:
1739320 - 财政年份:2017
- 资助金额:
$ 22.29万 - 项目类别:
Standard Grant
EconoMical, PsycHologicAl and Societal Impact of RanSomware (EMPHASIS)
RanSomware 的经济、心理和社会影响 (EMPHASIS)
- 批准号:
EP/P011861/1 - 财政年份:2017
- 资助金额:
$ 22.29万 - 项目类别:
Research Grant
Mathematical Analysis of the Dynamics of Complex Quantum Systems
复杂量子系统动力学的数学分析
- 批准号:
1716198 - 财政年份:2017
- 资助金额:
$ 22.29万 - 项目类别:
Standard Grant
SEEK (Steganalytic vidEo rEsearch frameworK)
SEEK(隐写分析视频研究框架)
- 批准号:
EP/N028554/1 - 财政年份:2016
- 资助金额:
$ 22.29万 - 项目类别:
Research Grant
NRT-DESE: Generating, Analyzing, and Understanding Sensory and Sequencing Information--A Trans-Disciplinary Graduate Training Program in Biosensing and Computational Biology
NRT-DESE:生成、分析和理解感官和测序信息——生物传感和计算生物学跨学科研究生培训项目
- 批准号:
1450032 - 财政年份:2015
- 资助金额:
$ 22.29万 - 项目类别:
Standard Grant
Texas Analysis and Mathematical Physics Symposium
德克萨斯分析与数学物理研讨会
- 批准号:
1412627 - 财政年份:2014
- 资助金额:
$ 22.29万 - 项目类别:
Standard Grant
CAREER: Dynamics of complex quantum systems, scaling limits and renormalization
职业:复杂量子系统的动力学、尺度限制和重正化
- 批准号:
1151414 - 财政年份:2012
- 资助金额:
$ 22.29万 - 项目类别:
Standard Grant
Dynamics of complex quantum systems with randomness and nonlinearities
具有随机性和非线性的复杂量子系统的动力学
- 批准号:
1009448 - 财政年份:2010
- 资助金额:
$ 22.29万 - 项目类别:
Standard Grant
New, GK-12: A Multi-Disciplinary Research and Teaching Program in Biomedical Engineering for Discovery and Understanding of Cell Communication
新产品,GK-12:生物医学工程中的多学科研究和教学项目,旨在发现和理解细胞通讯
- 批准号:
0841259 - 财政年份:2009
- 资助金额:
$ 22.29万 - 项目类别:
Continuing Grant
相似海外基金
State collusion with Loyalist paramilitaries in Northern Ireland 1968-98
1968-98 年国家与北爱尔兰效忠派准军事组织勾结
- 批准号:
2885422 - 财政年份:2023
- 资助金额:
$ 22.29万 - 项目类别:
Studentship
Collusion or Unreasonable Rules: Evidence from Chinese IPO Underpricing
共谋或不合理规则:来自中国IPO抑价的证据
- 批准号:
2752320 - 财政年份:2022
- 资助金额:
$ 22.29万 - 项目类别:
Studentship
Theoretical and Empirical Analysis on Collusion
共谋的理论与实证分析
- 批准号:
21H04402 - 财政年份:2021
- 资助金额:
$ 22.29万 - 项目类别:
Grant-in-Aid for Scientific Research (A)
Price Transparency, Search, and Collusion in Markets
市场中的价格透明度、搜索和共谋
- 批准号:
DP210102321 - 财政年份:2021
- 资助金额:
$ 22.29万 - 项目类别:
Discovery Projects
Empire, Collusion, Terror and Anglo-Irish Relations, 1966-1998.
帝国、勾结、恐怖和英爱关系,1966-1998。
- 批准号:
2311335 - 财政年份:2019
- 资助金额:
$ 22.29万 - 项目类别:
Studentship
Empirical study of collusion
共谋的实证研究
- 批准号:
18H03643 - 财政年份:2018
- 资助金额:
$ 22.29万 - 项目类别:
Grant-in-Aid for Scientific Research (A)
A Supply Side Rationale for Wage Floors: Evidence on Worker Collusion
工资底线的供给方原理:工人共谋的证据
- 批准号:
1658937 - 财政年份:2017
- 资助金额:
$ 22.29万 - 项目类别:
Continuing Grant
Collaborative Research: Communication, Cartels and Collusion
合作研究:沟通、卡特尔和共谋
- 批准号:
1625917 - 财政年份:2016
- 资助金额:
$ 22.29万 - 项目类别:
Standard Grant
Collaborative Research: Communication, Cartels and Collusion
合作研究:沟通、卡特尔和共谋
- 批准号:
1626783 - 财政年份:2016
- 资助金额:
$ 22.29万 - 项目类别:
Standard Grant
Designing collusion-proof kidney exchange mechanisms
设计防共谋的肾脏交换机制
- 批准号:
16K03567 - 财政年份:2016
- 资助金额:
$ 22.29万 - 项目类别:
Grant-in-Aid for Scientific Research (C)














{{item.name}}会员




