Abstract
The widespread use of smartphones worldwide has led to a corresponding rise in the number of mobile applications available for Android devices. These apps offer users convenient ways to perform various daily tasks, but their proliferation has also created an environment in which attackers can steal sensitive information. Insecure options employed by many app developers create vulnerabilities that can be exploited by attackers to gain access to most smartphones. While existing methods can detect malware during app installation, they do not sufficiently address post-installation attacks, such as those resulting from fake apps or Man-in-the-Disk (MitD) attacks. To address this issue, the current study conducted research on post-installation attacks, including data leakage, malware injection, repackaging, reverse engineering, privilege escalation, and UI spoofing. MitD attacks are particularly challenging to counter, so, to mitigate this risk, the Post-Installation App Detection Method is proposed to monitor and regulate sensitive information flow and prevent MitD attacks.
Publisher
Engineering, Technology & Applied Science Research
Reference20 articles.
1. J. Kumar and G. Ranganathan, "Malware Attack Detection in Large Scale Networks using the Ensemble Deep Restricted Boltzmann Machine," Engineering, Technology & Applied Science Research, vol. 13, no. 5, pp. 11773–11778, Oct. 2023.
2. M. Kireet, P. Rachala, M. S. Rao, and R. Sreerangam, "Investigation Of Contemporary Attacks In Android Apps," International Journal of Scientific & Technology Research, vol. 8, no. 12, pp. 1789–1794, 2019.
3. S. Nasiri, M. T. Sharabian, and M. Aajami, "Using Combined One-Time Password for Prevention of Phishing Attacks," Engineering, Technology & Applied Science Research, vol. 7, no. 6, pp. 2328–2333, Dec. 2017.
4. Y. Sun et al., "Detecting Malware Injection with Program-DNS Behavior," in 2020 IEEE European Symposium on Security and Privacy (EuroS&P), Genoa, Italy, Sep. 2020, pp. 552–568.
5. M. Conti, N. Dragoni, and V. Lesyk, "A Survey of Man In The Middle Attacks," IEEE Communications Surveys & Tutorials, vol. 18, no. 3, pp. 2027–2051, 2016.