Large-Scale Analysis of Remote Code Injection Attacks in Android Apps

المؤلفون المشاركون

Choi, Hyunwoo
Kim, Yongdae

المصدر

Security and Communication Networks

العدد

المجلد 2018، العدد 2018 (31 ديسمبر/كانون الأول 2018)، ص ص. 1-17، 17ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2018-04-17

دولة النشر

مصر

عدد الصفحات

17

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

It is pretty well known that insecure code updating procedures for Android allow remote code injection attack.

However, other than codes, there are many resources in Android that have to be updated, such as temporary files, images, databases, and configurations (XML and JSON).

Security of update procedures for these resources is largely unknown.

This paper investigates general conditions for remote code injection attacks on these resources.

Using this, we design and implement a static detection tool that automatically identifies apps that meet these conditions.

We apply the detection tool to a large dataset comprising 9,054 apps, from three different types of datasets: official market, third-party market, and preinstalled apps.

As a result, 97 apps were found to be potentially vulnerable, with 53 confirmed as vulnerable to remote code injection attacks.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Choi, Hyunwoo& Kim, Yongdae. 2018. Large-Scale Analysis of Remote Code Injection Attacks in Android Apps. Security and Communication Networks،Vol. 2018, no. 2018, pp.1-17.
https://search.emarefa.net/detail/BIM-1213986

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Choi, Hyunwoo& Kim, Yongdae. Large-Scale Analysis of Remote Code Injection Attacks in Android Apps. Security and Communication Networks No. 2018 (2018), pp.1-17.
https://search.emarefa.net/detail/BIM-1213986

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Choi, Hyunwoo& Kim, Yongdae. Large-Scale Analysis of Remote Code Injection Attacks in Android Apps. Security and Communication Networks. 2018. Vol. 2018, no. 2018, pp.1-17.
https://search.emarefa.net/detail/BIM-1213986

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1213986