• Home
  • Search
  • Large-Scale Analysis of Remote Code Injection Attacks in Android Apps
  • Open Access IconOpen Access
  • Cite Icon12
  • https://doi.org/10.1155/2018/2489214Copy DOI Icon

Large-Scale Analysis of Remote Code Injection Attacks in Android Apps

Show More
  • Abstract
  • Highlights & Summary
  • PDF
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

It is pretty well known that insecure code updating procedures for Android allow remote code injection attack. However, other than codes, there are many resources in Android that have to be updated, such as temporary files, images, databases, and configurations (XML and JSON). Security of update procedures for these resources is largely unknown. This paper investigates general conditions for remote code injection attacks on these resources. Using this, we design and implement a static detection tool that automatically identifies apps that meet these conditions. We apply the detection tool to a large dataset comprising 9,054 apps, from three different types of datasets: official market, third-party market, and preinstalled apps. As a result, 97 apps were found to be potentially vulnerable, with 53 confirmed as vulnerable to remote code injection attacks.

Loading PDF

Similar Papers
  • Conference Article
  • Citations1

Remote Injected Code Behavior Analysis using Code Refactor

  • Jun 24, 2022
  • Qian Zhang +3
  • Book Chapter

Legal Implications of Emerging Approaches to War

  • Jan 01, 2014
  • William H Boothby
  • Research Article

Stochastic Models for Remote Timing Attacks

  • Jul 01, 2025
  • Proceedings on Privacy Enhancing Technologies
  • Simone Bozzolan +5
  • Research Article
  • Citations46

Are free Android app security analysis tools effective in detecting known vulnerabilities?

  • Aug 05, 2019
  • Empirical Software Engineering
  • Venkatesh-Prasad Ranganath +1
  • Conference Article
  • Citations1

Smartphone-based Tool for Two-Spotted Spider Mite Detection in Strawberry

  • Jul 12, 2021
  • 2021 ASABE Annual International Virtual Meeting, July 12-16, 2021
  • Congliang Zhou +5
  • Research Article
  • Citations7

Static Detection of Event-based Races in Android Apps

  • Mar 19, 2018
  • ACM SIGPLAN Notices
  • Yongjian Hu +1
  • Conference Article
  • Citations2

IoTHaven: An Online Defense System to Mitigate Remote Injection Attacks in Trigger-action IoT Platforms

  • Jul 10, 2024
  • Md Morshed Alam +2
  • PDF
  • Research Article
  • Citations9

Understanding and Statically Detecting Synchronization Performance Bugs in Distributed Cloud Systems

  • Jan 01, 2019
  • IEEE Access
  • Chen Zhang +3
  • Research Article
  • Citations66

Light-Weight, Inter-Procedural and Callback-Aware Resource Leak Detection for Android Apps

  • Nov 01, 2016
  • IEEE Transactions on Software Engineering
  • Tianyong Wu +6
  • Book Chapter
  • Citations12

Static Analysis of Android Apps Interaction with Automotive CAN

  • Jan 01, 2018
  • Federica Panarotto +4
  • Book Chapter
  • Citations183

Cache Based Remote Timing Attack on the AES

  • Jan 01, 2006
  • Onur Acıiçmez +2
  • Conference Article
  • Citations88

Revisiting Android reuse studies in the context of code obfuscation and library usages

  • May 31, 2014
  • Mario Linares-Vásquez +3
  • Conference Article
  • Citations84

ATVHunter: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android Applications

  • May 01, 2021
  • Xian Zhan +6
  • Conference Article
  • Citations9

Unintentional bugs to vulnerability mapping in Android applications

  • May 01, 2015
  • Garima Bajwa +3
  • Research Article
  • Citations9

Automatic Detection for Privacy Violations in Android Applications

  • Apr 15, 2022
  • IEEE Internet of Things Journal
  • Qian Luo +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.