Risks behind Device Information Permissions in Android OS

Alshehri, Ali and Hewins, Anthony and McCulley, Maria and Alshahrani, Hani and Fu, Huirong and Zhu, Ye (2017) Risks behind Device Information Permissions in Android OS. Communications and Network, 09 (04). pp. 219-234. ISSN 1949-2421

[thumbnail of CN_2017110914334369.pdf] Text
CN_2017110914334369.pdf - Published Version

Download (1MB)

Abstract

In the age of smartphones, people do most of their daily work using their smartphones due to significant improvement in smartphone technology. When comparing different platforms such as Windows, iOS, Android, and Blackberry, Android has captured the highest percentage of total market share [1]. Due to this tremendous growth, cybercriminals are encouraged to penetrate various mobile marketplaces with malicious applications. Most of these applications require device information permissions aiming to collect sensitive data without user’s consent. This paper investigates each element of system information permissions and illustrates how cybercriminals can harm users’ privacy. It presents some attack scenarios using READ_PHONE_STATE permission and the risks behind it. In addition, this paper refers to possible attacks that can be performed when additional permissions are combined with READ_PHONE_STATE permission. It also discusses a proposed solution to defeat these types of attacks.

Item Type: Article
Subjects: Oalibrary Press > Computer Science
Depositing User: Managing Editor
Date Deposited: 02 Dec 2022 04:38
Last Modified: 20 Sep 2023 07:09
URI: http://asian.go4publish.com/id/eprint/539

Actions (login required)

View Item
View Item