首页> 外文期刊>Journal of computer security >Do not jail my app: Detecting the Android plugin environments by time lag contradiction
【24h】

Do not jail my app: Detecting the Android plugin environments by time lag contradiction

机译:不要监狱我的应用程序:通过时间滞后矛盾检测Android插件环境

获取原文
获取原文并翻译 | 示例
           

摘要

Many Android apps today face problems such as the large application package (APK) size, frequent updates, and so on. The Android plugin technology provides a solution for app developers, allowing a running app to dynamically load and execute a separate APK file without installing it in the system. These dynamically loaded APKs are called plugins. In Android app markets, many multi-instance apps abuse this technology to load normal social apps as plugins. While satisfying the users' demand for logging into multiple accounts simultaneously, it brings new security threats to the legitimate apps. Sensitive API invocations can be hijacked and private data becomes accessible to malicious multi-instance apps. Therefore, identifying the running environments becomes necessary. In this paper, we propose a novel detection mechanism, named PluginAssassin, to identify whether an app is running as a plugin. PluginAssassin uses the time ratio of different activity launching procedures to determine the running environment, conforming to the observed time lag contradiction phenomenon. We also present a mitigation mechanism for the Delta T attack specific to our approach. We collect 50 multi-instance apps from two app markets and implement PluginAssassin in five popular social apps. We assess the effectiveness on three devices and the experimental results show that PluginAssassin can detect plugin environments effectively.
机译:许多Android应用程序今天面临着大型应用程序包(APK)大小,频繁更新等问题。 Android插件技术为应用程序开发人员提供了一个解决方案,允许运行的应用程序动态加载并执行单独的APK文件而不在系统中安装。这些动态加载的APKS称为插件。在Android App Markets中,许多多实例应用程序滥用该技术将正常的社交应用程序作为插件加载。虽然满足用户同时登录多个帐户的用户的需求,但它为合法应用程序带来了新的安全威胁。敏感API调用可以劫持,并且可恶意多实例应用程序可以访问私有数据。因此,识别运行环境变得必要。在本文中,我们提出了一种新颖的检测机制,命名为pluginassass,以识别应用程序是否作为插件运行。 pluginassassin使用不同活动发射程序的时间比来确定运行环境,符合观察到的时间滞后矛盾现象。我们还为我们的方法提出了一种减缓机制。我们从两个App Markets中收集50个多实例应用程序,并在五个流行的社交应用程序中实现PlugInassAss。我们评估三个设备的有效性,实验结果表明,插件群体可以有效地检测插件环境。

著录项

  • 来源
    《Journal of computer security》 |2020年第2期|269-293|共25页
  • 作者单位

    Renmin Univ China Sch Informat Beijing Peoples R China|Renmin Univ China Key Lab DEKE MOE Beijing Peoples R China;

    Renmin Univ China Sch Informat Beijing Peoples R China|Renmin Univ China Key Lab DEKE MOE Beijing Peoples R China;

    Renmin Univ China Sch Informat Beijing Peoples R China|Renmin Univ China Key Lab DEKE MOE Beijing Peoples R China;

    Renmin Univ China Sch Informat Beijing Peoples R China|Renmin Univ China Key Lab DEKE MOE Beijing Peoples R China;

  • 收录信息 美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Android; plugin environment; time lag contradiction; time ratio; Delta T attack;

    机译:Android;插件环境;时间滞后矛盾;时间比率;三角洲T攻击;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号