Authors
Pu Sun, Sen Chen, Lingling Fan, Pengfei Gao, Fu Song, Min Yang
Publication date
2023/2
Journal
Frontiers of Computer Science
Volume
17
Issue
1
Pages
171801
Publisher
Higher Education Press
Description
Activity hijacking is one of the most powerful attacks in Android. Though promising, all the prior activity hijacking attacks suffer from some limitations and have limited attack capabilities. They no longer pose security threats in recent Android due to the presence of effective defense mechanisms. In this work, we propose the first automated and adaptive activity hijacking attack, named VenomAttack, enabling a spectrum of customized attacks (e.g., phishing, spoofing, and DoS) on a large scale in recent Android, even the state-of-the-art defense mechanisms are deployed. Specifically, we propose to use hotpatch techniques to identify vulnerable devices and update attack payload without re-installation and re-distribution, hence bypassing offline detection. We present a newly-discovered flaw in Android and a bug in derivatives of Android, each of which allows us to check if a target app is running in the background or …
Total citations
2023202431
Scholar articles
P Sun, S Chen, L Fan, P Gao, F Song, M Yang - Frontiers of Computer Science, 2023