首页    期刊浏览 2025年04月30日 星期三
登录注册

文章基本信息

  • 标题:Unix Domain Sockets Applied in Android Malware Should Not Be Ignored
  • 本地全文:下载
  • 作者:Xu Jiang ; Dejun Mu ; Huixiang Zhang
  • 期刊名称:Information
  • 电子版ISSN:2078-2489
  • 出版年度:2018
  • 卷号:9
  • 期号:3
  • 页码:54-69
  • DOI:10.3390/info9030054
  • 出版社:MDPI Publishing
  • 摘要:Increasingly, malicious Android apps use various methods to steal private user data without their knowledge. Detecting the leakage of private data is the focus of mobile information security. An initial investigation found that none of the existing security analysis systems can track the flow of information through Unix domain sockets to detect the leakage of private data through such sockets, which can result in zero-day exploits in the information security field. In this paper, we conduct the first systematic study on Unix domain sockets as applied in Android apps. Then, we identify scenarios in which such apps can leak private data through Unix domain sockets, which the existing dynamic taint analysis systems do not catch. Based on these insights, we propose and implement JDroid, a taint analysis system that can track information flows through Unix domain sockets effectively to detect such privacy leaks.
  • 关键词:Android; information flows; Unix domain sockets; private data; malware Android ; information flows ; Unix domain sockets ; private data ; malware
国家哲学社会科学文献中心版权所有