【24h】

Attacks on Android banking applications

机译:对Android银行应用程序的攻击

获取原文
获取原文并翻译 | 示例

摘要

Today, over 50 % of the world population use mobile applications to manage every day their daily activities. These offer the opportunities to use multiple services such as e-commerce, social networks and e-banking. But, they don't always respect the security requirements such as privacy and data user protection. And the security breaches give to attackers the possibility to perform several attacks on mobile devices by compromising mobile applications. We are interested in this paper to the security of mobile banking applications. For this, we have made the reverse engineering of an Android application to show its weaknesses and to show the possibility to make a DDOS attack to a bank server via a compromised mobile banking application. In this paper we will present some applications security issues offered by Android security model, we will make a reverse engineering of an Android banking application, and then do static analysis of its code to detect its weaknesses. After that, it become possible to insert a malicious activity that will help us to take control of the smartphone and make a DDOS attack on a simulated bank server. Finally, we will propose some measures that will help developers to enhance their mobile applications security.
机译:如今,全球超过50%的人口使用移动应用程序来管理其日常活动。这些提供了使用多种服务的机会,例如电子商务,社交网络和电子银行。但是,他们并不总是尊重诸如隐私和数据用户保护之类的安全要求。安全漏洞使攻击者有可能通过破坏移动应用程序而对移动设备进行多种攻击。我们对本文对移动银行应用程序的安全性感兴趣。为此,我们对Android应用程序进行了逆向工程,以显示其弱点,并展示通过受损的移动银行应用程序对银行服务器进行DDOS攻击的可能性。在本文中,我们将介绍Android安全模型提供的一些应用程序安全性问题,我们将对Android银行业务应用程序进行反向工程,然后对其代码进行静态分析以检测其弱点。之后,可以插入恶意活动,这将有助于我们控制智能手机并在模拟银行服务器上发起DDOS攻击。最后,我们将提出一些措施,以帮助开发人员增强其移动应用程序的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号