Intersection Automata Based Model for Android Application Collusion

Shweta Bhandari, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur · 2016

Android applications need to access and share user's sensitive data. To maintain user's privacy and related data security, it is essential to protect this data. Android security framework enforces permission protected model but it has been shown that applications can bypass this security model. Attacks based on such unauthorized privileges are known as Inter-Component Communication (ICC) Collusion Attacks. In this paper, we propose, a novel automaton framework that allows effective detection of intent based collusion. Our detection framework operates at the component-level. To evaluate our proposal, we developed 14 applications and took 4 applications from Google Play Store. We took all possible combinations from the set of 21 applications. We tested our approach on 210 pairs of applications derived from the set of 21 applications. Time and space complexity of our proposed approach isO(n) where n is the number of components in all the applications under analysis. The experimental results demonstrate that our technique is scalable to application sizing and more efficient as compared to other state of the art approaches.

Read the paper · More papers on PaperTik