首页> 外文OA文献 >An android-based trojan spyware to study the notificationlistener service vulnerability
【2h】

An android-based trojan spyware to study the notificationlistener service vulnerability

机译:基于Android的木马间谍软件,用于研究NotificationListener服务漏洞

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Security attacks continue to emerge on daily basis due to the fast growth in the number of smart devices and mobile applications. Attacks take different malware forms such as Spyware and Trojan exploiting different operating system vulnerabilities, specially the well known vulnerable operating system; Android OS. In this paper, we study the malicious use of the “NotificationListener” service in Android 4.3 and 5.0. A Trojan application, known as SMS backup, is developed to spy the notifications of other applications. Such an application requires only two permissions that include “Notification Access” and “Internet”. These permissions are used to extract and send user's messages of other applications to the attacker's email through Internet. Our malware is able to alter and/or delete the notification before being displayed. For experimental results, the malware was tested against notifications of WhatsApp, BBM, SMS, and Facebook messenger using different Android versions including Lollipop 5.0. Experiments show that our malware succeeded against all the tested applications running Android version 4.3. Moreover, BBM and SMS messages are still extractable in the newer version of Android (Lollipop 5.0).
机译:由于智能设备和移动应用程序数量的快速增长,安全攻击每天都在继续出现。攻击采取不同的恶意软件形式,例如利用不同的操作系统漏洞(特别是众所周知的易受攻击的操作系统)的间谍软件和木马。 Android作业系统。在本文中,我们研究了Android 4.3和5.0中“ NotificationListener”服务的恶意使用。开发了一种称为SMS备份的Trojan应用程序,以监视其他应用程序的通知。这样的应用程序仅需要两个权限,包括“通知访问”和“ Internet”。这些权限用于通过Internet提取其他应用程序的用户消息并将其发送到攻击者的电子邮件。我们的恶意软件能够在显示之前更改和/或删除通知。为了获得实验结果,该恶意软件使用包括Lollipop 5.0在内的不同Android版本针对WhatsApp,BBM,SMS和Facebook Messenger的通知进行了测试。实验表明,我们的恶意软件已成功击败了所有经过测试的运行Android 4.3版的应用程序。此外,BBM和SMS消息仍可从更新版本的Android(Lollipop 5.0)中提取。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号