Taurus: Preventing Stealthy SMS Activities on Android

Article Preview

Abstract:

This study introduces a direct and intuitive method to resist certain apps from sending SMS message stealthily. According to the heuristic analysis and observation, it is apparently that a SMS message, which has the textual content originated from user's entering manually, is obviously benign. We use this principle to design a serious of SMS examination and verification procedures, in order to force all SMS messages to be verified automatically before delivering them actually. A package named as Taurus, which is comprised of several new components, are developed in the Android framework in this study. The evaluation shows that Taurus, which examines all outgoing and detects potentially malicious SMS messages, has an excellent performance with reasonable memory usage overhead.

You might also be interested in these eBooks

Info:

Periodical:

Pages:

960-964

Citation:

Online since:

May 2015

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2015 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

* - Corresponding Author

[1] K. Presti: Kaspersky: SMS Trojans Account For Over Half Of Smartphone Malware, http: /www. crn. com/news/security/240012810/kaspersky-sms-trojans-account-for-over-half-of-smartphone-malware. htm, 2012, accessed: February (2012).

Google Scholar

[2] S. McGlaun: 500, 000 Android users in China infected with SMSZombie, http: / www. slashgear. com/500000-android-users-in-china-infected-with-sms-zombie-20243293/, 2012, accessed: August (2012).

Google Scholar

[3] T. S. Labs: New Virus SMSZombie. A Discovered by TrustGo Security Labs, on http: / blog. trustgo. com/SMSZombie/, 2012, accessed: August (2012).

Google Scholar

[4] A. Conway: Android Trojan used to create simple SMS spam botnet, on http: / blog. cloudmark. com/2012/12/16/android-trojan-used-to-create-simple-sms-spam-botnet, 2012, accessed: December (2012).

DOI: 10.1002/sec.577

Google Scholar

[5] Pikspam: An sms spam botnet, http: /www. symantec. com/connect/blogs/pikspam-sms-spam -botnet, 2012, accessed: December (2012).

Google Scholar

[6] New Trojan steals short messages, on http: /news. drweb. com/show/?i=3549&lng=en&=p=0.

Google Scholar

[7] P. Ramos: Don't pay high phone bills: SMS Trojans can trick you via premium-rate numbers, on http: /www. welivesecurity. com/2012/11/29/android-sms-trojan-tricks-you-into-premium-rate-calls/", accessed: November (2012).

Google Scholar

[8] H. S. Xu, Rubin and R. Anderson: Aurasium: Practical policy enforcement for android applications, in Proceedings of the 21st USENIX Security Symposium, (2012).

Google Scholar

[9] B. -G. C. William Enck, Peter Gilbert: TaintDroid: an information-flow tracking system for Realtime privacy monitoring on smartphones, in Proceedings of the 9th USENIX conference on Op-erating systems design and implementation, (2010).

Google Scholar

[10] D. B. Jarabek, Chris and J. Aycock: ThinAV: truly lightweight mobile cloud-based anti-malware, in Proceedings of the 28th Annual Computer Security Applications Conference, ser. ACM, (2012).

DOI: 10.1145/2420950.2420983

Google Scholar

[11] H. Y. s. L. Jerry Cheng, Startsky H.Y. Wong: Smartsiren: Virus detection and alert for smartphones, in Proceedings of the 5th international conference on Mobile systems, applications and services, ser. ACM, (2007).

DOI: 10.1145/1247660.1247690

Google Scholar

[12] U. E. Asaf Shabtai, Uri Kanonov: Andromaly: a behavioral malware detection framework for Android devices, in Journal of Intelligent Information Systems, ser. 38. 1, 2012, p.161–190.

DOI: 10.1007/s10844-010-0148-x

Google Scholar

[13] W. Z. X. J. Yajin Zhou, Zhi Wang: Hey, you, get off of my market: Detecting malicious apps in official and alternative Android markets, in Proceedings of the 19th Annual Network and Distributed System Security Symposium, (2012).

Google Scholar

[14] Android Developers Reference: SmsManager, on http: /developer. android. com/reference /android/telephony/gsm/SmsManager. html.

Google Scholar

[15] Contagio mobile, on http: /contagiominidump. blogspot. tw/, 2013, accessed: July (2013).

Google Scholar

[16] X. Jiang: Security alert: New Android malware HippoSMS found in alternative android markets, on http: /www. csc. ncsu. edu/faculty/jiang/HippoSMS/, (2011).

Google Scholar

[17] First SMS Trojan detected for smartphones running android, on http: /www. kaspersky. com/ news?id=207576158, (2010).

Google Scholar

[18] T. Strazzere: GGtracker technical tear down, on https: /blog. lookout. com/wp-content/uploads /2011/06/GGTracker-Teardown_Lookout-Mobile-Security. pdf, (2011).

Google Scholar