Title
Unix Domain Sockets Applied In Android Malware Should Not Be Ignored
Abstract
Increasingly, malicious Android apps use various methods to steal private user data without their knowledge. Detecting the leakage of private data is the focus of mobile information security. An initial investigation found that none of the existing security analysis systems can track the flow of information through Unix domain sockets to detect the leakage of private data through such sockets, which can result in zero-day exploits in the information security field. In this paper, we conduct the first systematic study on Unix domain sockets as applied in Android apps. Then, we identify scenarios in which such apps can leak private data through Unix domain sockets, which the existing dynamic taint analysis systems do not catch. Based on these insights, we propose and implement JDroid, a taint analysis system that can track information flows through Unix domain sockets effectively to detect such privacy leaks.
Year
DOI
Venue
2018
10.3390/info9030054
INFORMATION
Keywords
Field
DocType
Android, information flows, Unix domain sockets, private data, malware
Information flow (information theory),Data mining,Android (operating system),Computer science,Unix,Information security,Exploit,Security analysis,Taint checking,Malware,Operating system
Journal
Volume
Issue
Citations 
9
3
0
PageRank 
References 
Authors
0.34
7
3
Name
Order
Citations
PageRank
Xu Jiang120.71
Dejun Mu2194.78
Huixiang Zhang3144.10