Analysis of dynamic code updating in Android with security perspective. (1st May 2019)
- Record Type:
- Journal Article
- Title:
- Analysis of dynamic code updating in Android with security perspective. (1st May 2019)
- Main Title:
- Analysis of dynamic code updating in Android with security perspective
- Authors:
- Aysan, Ahmet I.
Sakiz, Fatih
Sen, Sevil - Abstract:
- Abstract : Attackers have been searching for security vulnerabilities to exploit in Android applications. Such security vulnerabilities include Android applications that could load code at runtime which helps attackers avoid detection by static analysis tools. In this study, an extensive analysis is conducted in order to see how attackers employ updating techniques to exploit such vulnerabilities and to assess the security risks of applications in the marketplace using these techniques. A comprehensive analysis was carried out on nearly 30, 000 applications collected from three different Android markets and two malware datasets. Static, dynamic and permission‐based analyses were employed in order to monitor malicious activities in such applications, and new malicious applications using updating techniques were discovered in Google Play. The results show that applications employing code updating techniques are on the rise. It is believed that this is the first study of its kind to monitor updating behaviours of applications during their execution. This analysis allows us to deeply analyse suspicious applications and thereby develop better security solutions.
- Is Part Of:
- IET information security. Volume 13:Number 3(2019)
- Journal:
- IET information security
- Issue:
- Volume 13:Number 3(2019)
- Issue Display:
- Volume 13, Issue 3 (2019)
- Year:
- 2019
- Volume:
- 13
- Issue:
- 3
- Issue Sort Value:
- 2019-0013-0003-0000
- Page Start:
- 269
- Page End:
- 277
- Publication Date:
- 2019-05-01
- Subjects:
- invasive software -- mobile computing -- program diagnostics -- Android (operating system)
security vulnerabilities -- Android applications -- static analysis tools -- permission‐based analyses -- malicious applications -- code updating techniques -- malware datasets -- Google Play
Computer security -- Periodicals
Cryptography -- Periodicals
Computer networks -- Security measures -- Periodicals
Database security -- Periodicals
005.8 - Journal URLs:
- https://ietresearch.onlinelibrary.wiley.com/journal/17518717 ↗
http://digital-library.theiet.org/content/journals/iet-ifs ↗
http://www.ietdl.org/IET-IFS ↗
http://www.theiet.org/ ↗ - DOI:
- 10.1049/iet-ifs.2018.5316 ↗
- Languages:
- English
- ISSNs:
- 1751-8709
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4363.252660
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 16476.xml