Hiding Data in the Padding Area of Android Applications without Re-Packaging

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Anonymous attackers have been targeting the Android ecosystem for performing severe malicious activities. Despite the complement of various vulnerabilities by security researchers, new vulnerabilities are continuously emerging. In this paper, we introduce a new type of vulnerability that can be exploited to hide data in an application file, bypassing the Android’s signing policy. Specifically, we exploit padding areas that can be created by using the alignment option when applications are packaged. We present a proof-of-concept implementation for exploiting the vulnerability. Finally, we demonstrate the effectiveness of VeileDroid by using a synthetic application that hides data in the padding area and updates the data without re-signing and updating the application on an Android device. Copyright © 2022 The Institute of Electronics, Information and Communication Engineers.

키워드

Android applicationAPK filedata hiding
제목
Hiding Data in the Padding Area of Android Applications without Re-Packaging
저자
Jeon, G.Yi, J.H.Cho, H.
DOI
10.1587/transinf.2022NGL0003
발행일
2022-11
유형
Article
저널명
IEICE Transactions on Information and Systems
E105D
11
페이지
1928 ~ 1929