GUI-Squatting Attack : Automated Generation 2 of Android

semanticscholar(2019)

引用 0|浏览6
暂无评分
摘要
4 Abstract—Mobile phishing attacks, such as mimic mobile browser pages, masquerade as legitimate applications by leveraging 5 repackaging or clone techniques, have caused varied yet significant security concerns. Consequently, detection techniques have been 6 receiving increasing attention. However, many such detection methods are not well tested and may therefore still be vulnerable to new 7 types of phishing attacks. In this article, we propose a new attacking technique, named GUI-Squatting attack, which can generate 8 phishing apps (phapps) automatically and effectively on the Android platform. Our method adopts image processing and deep learning 9 algorithms, to enable powerful and large-scale attacks. We observe that a successful phishing attack requires two conditions, page 10 confusion and logic deception during attacks synthesis. We directly optimize these two conditions to create a practical attack. Our 11 experimental results reveal that existing phishing defenses are less effective against such emergent attacks and may, therefore, 12 stimulate more efficient detection techniques. To further demonstrate that our generated phapps can not only bypass existing 13 detection techniques, but also deceive real users, we conduct a human study and successfully steal users’ login information. The 14 human study also shows that different response messages (e.g., “Crash” and “Server failed”) after pressing the login button mislead 15 users to regard our phapps as functionality problems instead of security threats. Extensive experiments reveal that such newly 16 proposed attacks still remain mostly undetected, and are worth further exploration.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要