首页> 外文会议>International Conference on Software Engineering Research and Practice >Using Deep Packet Inspection to Detect Mobile Application Privacy Threats
【24h】

Using Deep Packet Inspection to Detect Mobile Application Privacy Threats

机译:使用深度数据包检测来检测移动应用程序隐私威胁

获取原文

摘要

Modern mobile and embedded devices hold increasing amounts of sensitive data, with little visibility into where that data is sent. Existing solutions tend to be platform-specific, targetting only Android or iOS. We present a technique and a develop a tool that can detect exfiltration of private data in a platform-independent way by utilizing deep packet inspection. We examine the techniques and patterns common to sensitive personal data attacks and evaluate our tool's effectiveness in detecting the exfiltration of sensitive data on known mobile malware. We learn that the majority of the known-malicious applications in our study were unable to exfiltrate contact information. Only one known-malicious application under test was able to connect to a remote server and send contact information. One known-malicious application under test was able to connect to a remote server and send contact information, which raises awareness in the software assurance community.
机译:现代移动和嵌入式设备持有越来越多的敏感数据,在发送数据的位置几乎没有可见性。现有解决方案往往是特定于平台的,仅针对Android或iOS。我们提出了一种技术和开发一种工具,可以通过利用深度分组检测以平台独立的方式检测私人数据的exfiltration。我们检查敏感个人数据攻击的技术和模式,并评估我们的工具在检测已知移动恶意软件上敏感数据的exfiltation的有效性。我们了解到,我们研究中的大多数已知恶意应用程序无法抵消联系信息。只有一个被测的已知恶意应用程序能够连接到远程服务器并发送联系信息。一个已知的恶意应用程序可以连接到远程服务器并发送联系信息,从而提高软件保障界的认识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号