返回
Inference attack in Android Activity based on program fingerprint
DOI:10.1016/j.jnca.2018.12.007.png)
摘要
En 中文
Private breach has always been an important threat to mobile security. Recent studies show that an attacker can infer users' private information through side channels, such as the use of runtime memory and network usage. For side-channel attacks, malicious applications generally run parallel in the background with a foreground application and stealthily collect side-channel information. In this paper, we analyze the relationship between memory changes and Activity transition, then use side-channel information to label an Activity and build an Activity signature database. We show how to use the runtime memory exposure to infer the Activity transition of the current application and use other side channels to infer its Activity interface. We demonstrate the effectiveness of the attacks with 5 popular applications that contain user sensitive information, and successfully inferred most of the Activity transition and Activity interface process. Moreover, we propose a protection scheme which can effectively resist side-channel attacks.
Keyword:
Android security
Side-channel attack
Activity inference
Program fingerprint
Protection
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
8
论文数:
3.6K
被引数:
1.1W
机构
引用论文
TinyLock: Affordable defense against smudge attacks on smartphone pattern lock systems
COMPUTERS & SECURITY
IF5.4
没有更多内容

