Abstract
Android is the world’s most utilized smartphone OS which consequently, also makes it an attractive target for attackers. The most representative method of hacking used against Android apps is known as repackaging. This attack method requires extensive knowledge about reverse engineering in order to modify and insert malicious codes into the original app. However, there exists an easier way which circumvents the limiting obstacle of the reverse engineering. We have discovered a method of exploiting the Android code-signing process in order to mount a malware as an example. We also propose a countermeasure to prevent this attack. In addition, as a proof-of-concept, we tested a malicious code based on our attack technique on a sample app and improved the java libraries related to code-signing/verification reflecting our countermeasure.
Author supplied keywords
Cite
CITATION STYLE
Cho, T., & Seo, S. H. (2015). A strengthened android signature management method. KSII Transactions on Internet and Information Systems, 9(3), 1210–1230. https://doi.org/10.3837/tiis.2015.03.021
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.