Punobot: Mobile botnet using push notification service in android

17Citations
Citations of this article
32Readers
Mendeley users who have this article in their library.
Get full text

Abstract

A botnet is a collection of computers compromised by attackers, which is being increasingly used to advance political or financial interests. Recently, mobile botnets that rely on compromised mobile devices are emerging due to their improvements in computation power and communication capability. To cope with mobile botnets, we need to anticipate and prevent their command and control (C&C) channels. In this paper, we explore a new C&C channel for mobile botnets that is based on the push notification service (PNS) of Android: Google Cloud Messaging for Android (GCM). We find that (1) the registration process of the GCM only checks the validity of Gmail address and (2) applications can hide received push messages from users. By exploiting these two vulnerabilities, we evaluate the feasibility of the push notification service-based mobile botnet (Punobot) in several aspects. We show that Punobot is stealthy, energy-efficient, and dangerous. We also recommend remedies that any PNSs should consider to eliminate their security weaknesses. © 2014 Springer International Publishing Switzerland.

Cite

CITATION STYLE

APA

Lee, H., Kang, T., Lee, S., Kim, J., & Kim, Y. (2014). Punobot: Mobile botnet using push notification service in android. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 8267 LNCS, pp. 124–137). Springer Verlag. https://doi.org/10.1007/978-3-319-05149-9_8

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free