Back to Search Start Over

Preventing the propagation of a new kind of illegitimate apps

Authors :
Alain Tchana
Giang Son Tran
Lavoisier Wapet
Daniel Hagimont
Centre National de la Recherche Scientifique - CNRS (FRANCE)
Institut National Polytechnique de Toulouse - Toulouse INP (FRANCE)
Université Toulouse III - Paul Sabatier - UT3 (FRANCE)
Université des Sciences et des Technologies de Hanoi - USTH (VIETNAM)
Université Toulouse - Jean Jaurès - UT2J (FRANCE)
Université Toulouse 1 Capitole - UT1 (FRANCE)
Institut National Polytechnique de Toulouse - INPT (FRANCE)
Système d’exploitation, systèmes répartis, de l’intergiciel à l’architecture (IRIT-SEPIA)
Institut de recherche en informatique de Toulouse (IRIT)
Université Toulouse 1 Capitole (UT1)
Université Fédérale Toulouse Midi-Pyrénées-Université Fédérale Toulouse Midi-Pyrénées-Université Toulouse - Jean Jaurès (UT2J)-Université Toulouse III - Paul Sabatier (UT3)
Université Fédérale Toulouse Midi-Pyrénées-Centre National de la Recherche Scientifique (CNRS)-Institut National Polytechnique (Toulouse) (Toulouse INP)
Université Fédérale Toulouse Midi-Pyrénées-Université Toulouse 1 Capitole (UT1)
Université Fédérale Toulouse Midi-Pyrénées
Hanoi University of Science and Technology (HUST)
Institut National Polytechnique (Toulouse) (Toulouse INP)
Source :
Future Generation Computer Systems, Future Generation Computer Systems, Elsevier, 2019, 94, pp.368-380. ⟨10.1016/j.future.2018.11.051⟩
Publication Year :
2019
Publisher :
Elsevier BV, 2019.

Abstract

International audience; A significant amount of apps submitted to mobile market places (MMP) are illegitimate, resulting in a negative publicity for these MMPs. To our knowledge, all scanning solutions in this domain only focus on the detection of illegitimate apps which mimic existing ones. However, recent attack analysis reveal the appearance of a new category of victims: enterprises which did not yet publish their app on the MMP. Thereby, an attacker may be one step ahead and publish a malicious app using the graphic identity of a trusted enterprise. Famous enterprises such as Blackberry, Netflix, and Niantic (Pokemon Go) have been subject of such attacks. We designed and implemented a security check system called IMAD (IllegitimateMobile App Detector) which is able to limit aforementioned attacks. The evaluation results show that IMAD can protect companies from such attacks with an acceptable error rate and at a low cost for MMPs.

Details

ISSN :
0167739X
Volume :
94
Database :
OpenAIRE
Journal :
Future Generation Computer Systems
Accession number :
edsair.doi.dedup.....1ee0df20340056a7637238b96ab33653