【24h】

Android spyware disease and medication

机译:Android间谍软件疾病和药物

获取原文
获取原文并翻译 | 示例

摘要

Android-based smartphones are gaining significant advantages on its counterparts in terms of market share among users. The increasing usage of Android OS make it ideal target for attackers. There is an urgent need to develop solutions that guard the user's privacy and can monitor, detect and block these Eavesdropping applications. In this paper, two proposed paradigm are presented. The first proposed paradigm is a spyware application to highlight the security weaknesses “disease”. The spy-ware application has been used to deeply understand the vulnerabilities in the Android operating system, and to study how the spy-ware can be developed to abuse these vulnerabilities for intercepting victim's privacy such as received SMS, incoming calls and outgoing calls. The spy-ware abuses the Internet service to transfer the intercepted information from victim's cell phone illegally to a cloud database. The Android OS permission subsystem and the broadcast receiver subsystem contribute to form a haven for the spy-ware by granting it absolute control to listen, intercept and track the victim privacy. The second proposed paradigm is a new detection paradigm “medication” based on fuzz testing technique to mitigate known vulnerabilities. In this proposal, anti-spy-ware solution “DroidSmartFuzzer” has been designed. The implementation of the anti-spy-ware application has been used to mitigate the risks of the mentioned attacks. It should be noted that the proposed paradigm “DroidSmart-Fuzzer” and its fuzzing test cases are designed not only to catch the proposed spy-ware application but also to catch any similar malicious application designed to intercept one or more of the listed privacies.
机译:就用户之间的市场份额而言,基于Android的智能手机正在获得与同类产品相当的优势。 Android OS的使用日益增加,使其成为攻击者的理想目标。迫切需要开发一种解决方案,以保护用户的隐私并可以监视,检测和阻止这些窃听应用程序。在本文中,提出了两个提出的范例。首先提出的范例是间谍软件应用程序,以突出显示安全漏洞“疾病”。间谍软件应用程序已用于深入了解Android操作系统中的漏洞,并研究了如何开发间谍软件以滥用这些漏洞来拦截受害者的隐私,例如接收到的SMS,呼入和呼出电话。间谍软件滥用互联网服务,将拦截的信息从受害者的手机非法传输到云数据库。 Android OS权限子系统和广播接收器子系统通过授予间谍软件绝对的控制权来侦听,拦截和跟踪受害者的隐私,从而为间谍软件形成了避风港。提出的第二个范例是一种基于模糊测试技术的新检测范例“药物”,以减轻已知漏洞。在此建议中,已设计了反间谍软件解决方案“ DroidSmartFuzzer”。反间谍软件应用程序的实施已用于减轻上述攻击的风险。应该注意的是,提议的范式“ DroidSmart-Fuzzer”及其模糊测试案例的目的不仅在于捕获提议的间谍软件应用程序,而且还捕获任何旨在拦截一个或多个所列隐私的类似恶意应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号