Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Ghost Installer in the Shadow: Security Analysis of App Installation on Android

Authors
Lee, YeonjoonLi, T.Zhang, N.Demetriou, S.Zha, M.Wang, X.Chen, K.Zhou, X.Han, X.Grace, M.
Issue Date
Jun-2017
Publisher
Institute of Electrical and Electronics Engineers Inc.
Citation
Proceedings - 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2017, pp.403 - 414
Indexed
OTHER
Journal Title
Proceedings - 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2017
Start Page
403
End Page
414
URI
https://scholarworks.bwise.kr/erica/handle/2021.sw.erica/11587
DOI
10.1109/DSN.2017.33
Abstract
Android allows developers to build apps with app installation functionality themselves with minimal restriction and support like any other functionalities. Given the critical importance of app installation, the security implications of the approach can be significant. This paper reports the first systematic study on this issue, focusing on the security guarantees of different steps of the App Installation Transaction (AIT). We demonstrate the serious consequences of leaving AIT development to individual developers: most installers (e.g., Amazon AppStore, DTIgnite, Baidu) are riddled with various security-critical loopholes, which can be exploited by attackers to silently install any apps, acquiring dangerous-level permissions or even unauthorized access to system resources. Surprisingly, vulnerabilities were found in all steps of AIT. The attacks we present, dubbed Ghost Installer Attack (GIA), are found to pose a realistic threat to Android ecosystem. Further, we developed both a user-app-level and a system-level defense that are innovative and practical. © 2017 IEEE.
Files in This Item
Go to Link
Appears in
Collections
COLLEGE OF COMPUTING > ERICA 컴퓨터학부 > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Lee, Yeon joon photo

Lee, Yeon joon
ERICA 소프트웨어융합대학 (ERICA 컴퓨터학부)
Read more

Altmetrics

Total Views & Downloads

BROWSE