iABC-AL: Active learning-based privacy leaks threat detection for iOS applications

Do iOS applications breach privacy? With plethora of iOS applications available in market, most users are unaware of security risks they pose. This includes breach of user’s privacy by sharing personal and sensitive Smartphone data without user’s consent. Apple follows strict code signing procedure...

Full description

Bibliographic Details
Main Authors: Arpita Jadhav Bhatt, Chetna Gupta, Sangeeta Mittal
Format: Article
Language:English
Published: Elsevier 2021-09-01
Series:Journal of King Saud University: Computer and Information Sciences
Subjects:
Online Access:http://www.sciencedirect.com/science/article/pii/S131915781830291X
id doaj-4eb8deda28ca4357b6eadd5ef5e5c8a2
record_format Article
spelling doaj-4eb8deda28ca4357b6eadd5ef5e5c8a22021-08-26T04:32:37ZengElsevierJournal of King Saud University: Computer and Information Sciences1319-15782021-09-01337769786iABC-AL: Active learning-based privacy leaks threat detection for iOS applicationsArpita Jadhav Bhatt0Chetna Gupta1Sangeeta Mittal2Corresponding author at: Department of Computer Science & IT, Jaypee Institute of Information Technology, A-10, Sector-62, Noida, Uttar Pradesh 201309, India.; Department of Computer Science & IT, Jaypee Institute of Information Technology, Noida, IndiaDepartment of Computer Science & IT, Jaypee Institute of Information Technology, Noida, IndiaDepartment of Computer Science & IT, Jaypee Institute of Information Technology, Noida, IndiaDo iOS applications breach privacy? With plethora of iOS applications available in market, most users are unaware of security risks they pose. This includes breach of user’s privacy by sharing personal and sensitive Smartphone data without user’s consent. Apple follows strict code signing procedure to ensure that applications are developed from trusted enterprises. However, past malware attacks on iOS devices have demonstrated that there is lack of protection from permission misuse by applications. While machine learning approaches offer promising results in detecting such malicious applications for Android operating system, there has been minimal research in extending them to iOS platform due to unavailability of labeled data-sets. In this study, we propose iABC-AL (iOS Application analyzer and Behavior Classifier using Active Learning), a framework to detect malicious iOS applications. The objective of iABC-AL is to protect permission induced user’s privacy risks by (i) maximizing precision of machine learning based classification models and (ii) minimize requirement of labeled training data-set. To attain the objective, iABC-AL framework incorporates category of application and active learning approaches. A total of 2325 iOS applications were evaluated. Empirical results demonstrate that the proposed approach achieves accuracy rate of 91.5% and increases precision of supervised approach by 14.5%.http://www.sciencedirect.com/science/article/pii/S131915781830291XiOS applicationsInformation securityStatic analysisPermission extractionActive learning
collection DOAJ
language English
format Article
sources DOAJ
author Arpita Jadhav Bhatt
Chetna Gupta
Sangeeta Mittal
spellingShingle Arpita Jadhav Bhatt
Chetna Gupta
Sangeeta Mittal
iABC-AL: Active learning-based privacy leaks threat detection for iOS applications
Journal of King Saud University: Computer and Information Sciences
iOS applications
Information security
Static analysis
Permission extraction
Active learning
author_facet Arpita Jadhav Bhatt
Chetna Gupta
Sangeeta Mittal
author_sort Arpita Jadhav Bhatt
title iABC-AL: Active learning-based privacy leaks threat detection for iOS applications
title_short iABC-AL: Active learning-based privacy leaks threat detection for iOS applications
title_full iABC-AL: Active learning-based privacy leaks threat detection for iOS applications
title_fullStr iABC-AL: Active learning-based privacy leaks threat detection for iOS applications
title_full_unstemmed iABC-AL: Active learning-based privacy leaks threat detection for iOS applications
title_sort iabc-al: active learning-based privacy leaks threat detection for ios applications
publisher Elsevier
series Journal of King Saud University: Computer and Information Sciences
issn 1319-1578
publishDate 2021-09-01
description Do iOS applications breach privacy? With plethora of iOS applications available in market, most users are unaware of security risks they pose. This includes breach of user’s privacy by sharing personal and sensitive Smartphone data without user’s consent. Apple follows strict code signing procedure to ensure that applications are developed from trusted enterprises. However, past malware attacks on iOS devices have demonstrated that there is lack of protection from permission misuse by applications. While machine learning approaches offer promising results in detecting such malicious applications for Android operating system, there has been minimal research in extending them to iOS platform due to unavailability of labeled data-sets. In this study, we propose iABC-AL (iOS Application analyzer and Behavior Classifier using Active Learning), a framework to detect malicious iOS applications. The objective of iABC-AL is to protect permission induced user’s privacy risks by (i) maximizing precision of machine learning based classification models and (ii) minimize requirement of labeled training data-set. To attain the objective, iABC-AL framework incorporates category of application and active learning approaches. A total of 2325 iOS applications were evaluated. Empirical results demonstrate that the proposed approach achieves accuracy rate of 91.5% and increases precision of supervised approach by 14.5%.
topic iOS applications
Information security
Static analysis
Permission extraction
Active learning
url http://www.sciencedirect.com/science/article/pii/S131915781830291X
work_keys_str_mv AT arpitajadhavbhatt iabcalactivelearningbasedprivacyleaksthreatdetectionforiosapplications
AT chetnagupta iabcalactivelearningbasedprivacyleaksthreatdetectionforiosapplications
AT sangeetamittal iabcalactivelearningbasedprivacyleaksthreatdetectionforiosapplications
_version_ 1721196199273299968