Exploitation and Detection of a Malicious Mobile Application

Date

2017-01

Authors

Nguyen, Thanh
McDonald, J. Todd
Glisson, William Bradley

Journal Title

Journal ISSN

Volume Title

Publisher

Proceedings of the 50th Hawaii International Conference on System Sciences

Abstract

Mobile devices are increasingly being embraced by both organizations and individuals in today’s society. Specifically, Android devices have been the prominent mobile device OS for several years. This continued amalgamation creates an environment that is an attractive attack target. The heightened integration of these devices prompts an investigation into the viability of maintaining non-compromised devices. Hence, this research presents a preliminary investigation into the effectiveness of current commercial anti-virus, static code analysis and dynamic code analysis engines in detecting unknown repackaged malware piggybacking on popular applications with excessive permissions. The contribution of this paper is two-fold. First, it provides an initial assessment of the effectiveness of anti-virus and analysis tools in detecting malicious applications and behavior in Android devices. Secondly, it provides process for inserting code injection attacks to stimulate a zero-day repackaged malware that can be used in future research efforts.

Description

A paper co-authored by William Glisson published in the Proceedings of the 50th Hawaii International Conference on System Sciences in 2017

Keywords

android, Code Injection, Malware analysis, smartphone security

Citation

Nguyen, T., McDonald, J. T., & Glisson, W. B. (2017). Exploitation and Detection of a Malicious Mobile Application. Proceedings of the 50th Hawaii International Conference on System Sciences (2017). Hawaii International Conference on System Sciences, p. 6181-6190. https://doi.org/10.24251/hicss.2017.747