Mobile and Ubiquitous Computing CS 525M: A Survey of Mobile Malware in the Wild Hiromu Enoki
Computer Science Dept. Worcester Polytechnic Institute (WPI)
1
Mobile and Ubiquitous Computing CS 525M: A Survey of Mobile Malware - - PowerPoint PPT Presentation
Mobile and Ubiquitous Computing CS 525M: A Survey of Mobile Malware in the Wild Hiromu Enoki Computer Science Dept. Worcester Polytechnic Institute (WPI) 1 Introduction Mobile Malware is fairly recent July 2004 Cabir virus came out on
1
July 2004 – Cabir virus came out on Symbian August 2010 – Fake Player on Android July 2012 – Find and Call on iOS
Amusement Credential Theft SMS spam Ransomware
2
E‐mail, contacts, passwords…
Exploits used by both users and adversaries
Permissions? OS features? App reviews?
3
Spam, Identity theft, DDoS, wiretapping were
4
All applications are reviewed by human iOS devices can only obtain apps through here, unless
Some applications may be reviewed Does not restrict installing apps from other markets
Security automatically reviewed by program Risky applications are reviewed by human Can install apps from other markets
5
4 – iOS 24 – Symbian 18 – Android
6
Categorized and counted how many permissions they
Attempted to determine malware from permission
Compared firmware release dates with root hack
7
8
Changing wallpapers, sending annoying SMS
Expected to decrease in number
9
Location, contacts, history, IMEI
$1.90 to $9.50 per user per month
10
Done in conjunction with phishing on desktops
11
Few dollars per minute or SMS
Mostly on Android and Symbian
12
13
Privacy concerns?
14
Asked for Name, Address, Company Name for
Asked 5800 Yen (~$60) to delete information from
About 661 out of 5510 infections actually paid (12%)
15
16
17
Only 4% of non‐malicious apps
Only 33% for non‐malicious apps
3.46 for Non‐malicious apps
18
Installing from unofficial markets System Backups Tethering Uninstalling apps
19
20
21
22
23
24