Detailed Information

Cited 40 time in webofscience Cited 56 time in scopus
Metadata Downloads

Repackaging Attack on Android Banking Applications and Its Countermeasures

Authors
Jung, Jin-HyukKim, Ju YoungLee, Hyeong-ChanYi, Jeong Hyun
Issue Date
Dec-2013
Publisher
SPRINGER
Keywords
Smartphone application vulnerability; Android app repackaging; Reverse engineering
Citation
WIRELESS PERSONAL COMMUNICATIONS, v.73, no.4, pp.1421 - 1437
Journal Title
WIRELESS PERSONAL COMMUNICATIONS
Volume
73
Number
4
Start Page
1421
End Page
1437
URI
http://scholarworks.bwise.kr/ssu/handle/2018.sw.ssu/11099
DOI
10.1007/s11277-013-1258-x
ISSN
0929-6212
Abstract
Although anyone can easily publish Android applications (or apps) in an app marketplace according to an open policy, decompiling the apps is also easy due to the structural characteristics of the app building process, making them very vulnerable to forgery or modification attacks. In particular, users may suffer direct financial loss if this vulnerability is exploited in security-critical private and business applications, such as online banking. In this paper, some of the major Android-based smartphone banking apps in Korea being distributed on either the Android Market or the third party market were tested to verify whether a money transfer could be made to an unintended recipient. The experimental results with real Android banking apps showed that an attack of this kind is possible without having to illegally obtain any of the sender's personal information, such as the senders public key certificate, the password to their bank account, or their security card. In addition, the cause of this vulnerability is analyzed and some technical countermeasures are discussed.
Files in This Item
Go to Link
Appears in
Collections
College of Information Technology > School of Software > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher YI, JEONG HYUN photo

YI, JEONG HYUN
College of Information Technology (School of Software)
Read more

Altmetrics

Total Views & Downloads

BROWSE