Protection against Code Obfuscation Attacks based on control dependencies in Android Systems - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2014

Protection against Code Obfuscation Attacks based on control dependencies in Android Systems

Résumé

In Android systems, an attacker can obfuscate an application code to leak sensitive information. TaintDroid is an information flow tracking system that protects private data in smartphones. But, TainDroid cannot detect control flows. Thus, it can be circumvented by an obfuscated code attack based on control dependencies. In this paper, we present a collection of obfuscated code attacks on TaintDroid system. We propose a technical solution based on a hybrid approach that combines static and dynamic analysis. We formally specify our solution based on two propagation rules. Finally, we evaluate our approach and show that we can avoid the obfuscated code attacks based on control dependencies by using these propagation rules.
Fichier principal
Vignette du fichier
bare_conf.pdf (307.19 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01010902 , version 1 (20-06-2014)

Identifiants

  • HAL Id : hal-01010902 , version 1

Citer

Mariem Graa, Nora Cuppens-Bouhlahia, Frédéric Cuppens, Ana Cavalli. Protection against Code Obfuscation Attacks based on control dependencies in Android Systems. TC 2014 : 8th International Workshop on Trustworthy Computing, Jun 2014, San Francisco, United States. ⟨hal-01010902⟩
313 Consultations
812 Téléchargements

Partager

Gmail Facebook X LinkedIn More