An APK Integrity Verification Mechanism for Third-party Android Marketplace

碩士 === 國立臺灣科技大學 === 資訊管理系 === 103 === The security issue of Android third-party markets has been one of the biggest problems in Android ecosystem. Without the authentication from official organization like Google, there might exist many malicious apps in the third-party markets. When users download...

Full description

Bibliographic Details
Main Authors: Shau-Kang Lu, 呂紹綱
Other Authors: Nai-Wei Lo
Format: Others
Language:en_US
Published: 2015
Online Access:http://ndltd.ncl.edu.tw/handle/95507803381385355269
id ndltd-TW-103NTUS5396058
record_format oai_dc
spelling ndltd-TW-103NTUS53960582016-11-06T04:19:39Z http://ndltd.ncl.edu.tw/handle/95507803381385355269 An APK Integrity Verification Mechanism for Third-party Android Marketplace 一個針對第三方Android市集所設計的行動裝置應用程式完整性驗證機制 Shau-Kang Lu 呂紹綱 碩士 國立臺灣科技大學 資訊管理系 103 The security issue of Android third-party markets has been one of the biggest problems in Android ecosystem. Without the authentication from official organization like Google, there might exist many malicious apps in the third-party markets. When users download apps from those insecure markets, they probably downloaded some malicious apps and the result can be serious. Minor impact can result in the privacy information leakage, while major impact can cause the loss of one's money or endanger one's life. In this paper, we present a mechanism for verifying the app integrity by combining the app fingerprint and an app database with whitelist / blacklist. Based on the fingerprint and database, we built a customized Android market called Secure Market. When someone upload apps to the Secure Market, the apps will be verified by the integrity verification mechanism immediately so that we can ensure the apps from Secure Market are almost secure. Finally, with collected normal/repackaged apps, the testing scenarios has shown that this integrity verification mechanism can almost help us to filter out the malicious apps, which are unqualified for uploading. Nai-Wei Lo 羅乃維 2015 學位論文 ; thesis 43 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立臺灣科技大學 === 資訊管理系 === 103 === The security issue of Android third-party markets has been one of the biggest problems in Android ecosystem. Without the authentication from official organization like Google, there might exist many malicious apps in the third-party markets. When users download apps from those insecure markets, they probably downloaded some malicious apps and the result can be serious. Minor impact can result in the privacy information leakage, while major impact can cause the loss of one's money or endanger one's life. In this paper, we present a mechanism for verifying the app integrity by combining the app fingerprint and an app database with whitelist / blacklist. Based on the fingerprint and database, we built a customized Android market called Secure Market. When someone upload apps to the Secure Market, the apps will be verified by the integrity verification mechanism immediately so that we can ensure the apps from Secure Market are almost secure. Finally, with collected normal/repackaged apps, the testing scenarios has shown that this integrity verification mechanism can almost help us to filter out the malicious apps, which are unqualified for uploading.
author2 Nai-Wei Lo
author_facet Nai-Wei Lo
Shau-Kang Lu
呂紹綱
author Shau-Kang Lu
呂紹綱
spellingShingle Shau-Kang Lu
呂紹綱
An APK Integrity Verification Mechanism for Third-party Android Marketplace
author_sort Shau-Kang Lu
title An APK Integrity Verification Mechanism for Third-party Android Marketplace
title_short An APK Integrity Verification Mechanism for Third-party Android Marketplace
title_full An APK Integrity Verification Mechanism for Third-party Android Marketplace
title_fullStr An APK Integrity Verification Mechanism for Third-party Android Marketplace
title_full_unstemmed An APK Integrity Verification Mechanism for Third-party Android Marketplace
title_sort apk integrity verification mechanism for third-party android marketplace
publishDate 2015
url http://ndltd.ncl.edu.tw/handle/95507803381385355269
work_keys_str_mv AT shaukanglu anapkintegrityverificationmechanismforthirdpartyandroidmarketplace
AT lǚshàogāng anapkintegrityverificationmechanismforthirdpartyandroidmarketplace
AT shaukanglu yīgèzhēnduìdìsānfāngandroidshìjísuǒshèjìdexíngdòngzhuāngzhìyīngyòngchéngshìwánzhěngxìngyànzhèngjīzhì
AT lǚshàogāng yīgèzhēnduìdìsānfāngandroidshìjísuǒshèjìdexíngdòngzhuāngzhìyīngyòngchéngshìwánzhěngxìngyànzhèngjīzhì
AT shaukanglu apkintegrityverificationmechanismforthirdpartyandroidmarketplace
AT lǚshàogāng apkintegrityverificationmechanismforthirdpartyandroidmarketplace
_version_ 1718391561888202752