首页> 外文期刊>Concurrency and computation: practice and experience >Detection of repackaged mobile applications through a collaborative approach
【24h】

Detection of repackaged mobile applications through a collaborative approach

机译:通过协作方法检测重新打包的移动应用程序

获取原文
获取原文并翻译 | 示例

摘要

Repackaged applications are based on genuine applications, but they subtlety include some modifications.rnIn particular, trojanized applications are one of the most dangerous threats for smartphones. Malware codernmay be hidden inside applications to access private data or to leak user credit. In this paper, we propose arncontract-based approach to detect such repackaged applications, where a contract specifies the set of legalrnactions that can be performed by an application. Current methods to generate contracts lack informationrnfrom real usage scenarios, thus being inaccurate and too coarse-grained. This may result either in generatingrntoo many false positives or in missing misbehaviors when verifying the compliance between the applicationrnand the contract. In the proposed framework, application contracts are generated dynamically by a centralrnserver merging execution traces collected and shared continuously by collaborative users executing the application.rnMore precisely, quantitative information extracted from execution traces is used to define a contractrndescribing the expected application behavior, which is deployed to the cooperating users. Then, every userrncan use the received contract to check whether the related application is either genuine or repackaged. Suchrna verification is based on an enforcement mechanism that monitors the application execution at run-time andrncompares it against the contract through statistical tests.
机译:重新打包的应用程序基于真实的应用程序,但它们的细微之处包括一些修改。特别是,木马化的应用程序是智能手机最危险的威胁之一。恶意软件代码可能隐藏在应用程序内部,以访问私有数据或泄露用户信誉。在本文中,我们提出了基于arncontract的方法来检测此类重新打包的应用程序,其中合同指定了可以由应用程序执行的一组法律诉讼。当前用于生成合同的方法缺乏来自实际使用情况的信息,因此不准确且过于粗糙。在验证应用程序与合同之间的合规性时,这可能会导致生成过多的误报或丢失不当行为。在提出的框架中,应用合同是由中央服务器动态生成的,该服务器合并由执行应用程序的协作用户连续收集和共享的执行迹线。更确切地说,将从执行迹线中提取的定量信息用于定义描述预期应用程序行为的契约,并进行部署给合作的用户。然后,每个用户都可以使用收到的合同来检查相关应用程序是真品还是重新包装。这样的验证基于一种强制机制,该机制在运行时监视应用程序的执行,并通过统计测试将其与合同进行比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号