首页> 外文会议>International Conference on Privacy and Security in Mobile Systems >Android - On-device detection of SMS catchers and sniffers
【24h】

Android - On-device detection of SMS catchers and sniffers

机译:Android - SMS捕集器和嗅探器的设备检测

获取原文

摘要

With 6.1 trillion text messages sent in 2010 alone, short message service (SMS) is still one of the most popular mobile communication services. Due to its continuing popularity, SMS technology is nowadays used in various fields of application. This also includes security-sensitive fields such as e-banking, or e-government. In these fields, SMS technology is for instance employed to authorize financial transactions or the creation of qualified electronic signatures. Modern smartphone platforms such as Google Android provide application developers with the means to include SMS functionality. This can be beneficial in most cases but also facilitates the implementation of malware that is able to send and receive SMS messages unnoticed by the legitimate end user. In this context, SMS sniffers and SMS catchers have recently attracted attention. This kind of malware intercepts incoming SMS messages either to spy on security-sensitive data transmitted via SMS or to receive SMS-based malware control commands. For security-sensitive SMS-based applications, SMS catchers pose a serious threat. A recent attack on SMS-based e-banking systems has employed SMS catchers on smartphones to steal 36.000.000 Euro from corporate and private bank accounts in Europe. Unfortunately, security software for smartphones is still in the fledging stages and current solutions are not able to reliably detect SMS catchers. To overcome this problem, we introduce different methods to detect SMS sniffers and SMS catchers on smartphones. We discuss benefits and limitations of the proposed methods and show how these methods can be assembled to a comprehensive detection workflow for SMS-based malware. By providing means to detect SMS catchers and sniffers on smartphones, our work contributes to the security of current and future SMS-based applications.
机译:使用2010年的6.1万亿条短信单独发送,短消息服务(SMS)仍然是最受欢迎的移动通信服务之一。由于其持续普及,现在在各种应用领域使用了SMS技术。这还包括安全敏感字段,例如电子银行或电子政务。在这些领域,SMS技术例如用于授权金融交易或创建合格的电子签名。谷歌Android等现代智能手机平台为应用程序开发人员提供包含SMS功能的方法。在大多数情况下,这可能是有益的,但还促进了能够发送和接收由合法最终用户无疑的短信的恶意软件的实现。在这方面,短信嗅探器和短信捕手最近引起了关注。这种恶意软件拦截传入的SMS消息,可以在通过SMS传输的安全敏感数据上间谍或接收基于SMS的恶意软件控制命令。对于基于安全敏感的SMS的应用,SMS捕集器构成了严重的威胁。最近对SMS的电子银行系统的攻击雇用了智能手机上的短信捕获者,从欧洲的企业和私人银行账户中窃取36.000.000欧元。遗憾的是,智能手机的安全软件仍处于逐步阶段,目前的解决方案无法可靠地检测SMS捕集器。为了克服这个问题,我们介绍了不同的方法来检测智能手机上的SMS嗅探器和短信捕集器。我们讨论了所提出的方法的好处和限制,并展示如何将这些方法组装到基于SMS的恶意软件的全面检测工作流程。通过提供智能手机上检测SMS捕集器和嗅探器的手段,我们的工作有助于当前和未来的基于SMS的应用程序的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号