Welcome to Journal of University of Chinese Academy of Sciences,Today is

›› 2015, Vol. 32 ›› Issue (6): 807-815.DOI: 10.7523/j.issn.2095-6134.2015.06.013

Previous Articles     Next Articles

An Android privacy leakage malicious application detection approach based on directed information flow

WU Jingzheng1,2, WU Yanjun1,2, WU Zhifei1, YANG Mutian1, LUO Tianyue1, WANG Yongji2,3   

  1. 1. Institute of Software, Chinese Academy of Sciences, Beijing 100190, China;
    2. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China;
    3. National Engineering Research Center for Foundamental Software, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
  • Received:2014-10-11 Revised:2015-03-27 Online:2015-11-15

Abstract:

Android devices occupy 81.9% of the total smart phone market. However, the malicious applications of Android system are increasing, and the detection technology has become the hot topic in security research. We propose a new Android detection approach of privacy leakage malicious application based on directed information flow. This approach first decompiles the application and analyzes the permissions. Then, it builds directed information flow model according to the privacy points. By tracking the flows of the points, the information flows are monitored and the privacy leakages are detected. We tested 7 985 applications and detected 357 privacy leakage ones. We analyzed one of the results and confirmed that it was indeed a privacy leakge appliction. The results show that this new approach has good detection capacity.

Key words: Android applicaiton, pricacy leakage, directed infromation flow, malicious application detectoin, decompile

CLC Number: