Beta
356933

Detection of Integrity Attacks on Permissions of Android-Based Mobile Apps: Security Evaluation on PayPal

Article

Last updated: 24 Dec 2024

Subjects

-

Tags

-

Abstract

The objective of this paper is to detect unauthorized modifications to genuine permissions of legitimate Android-based mobile apps in real-time, with demonstration on PayPal payment gateway mobile app. The scientific value of this work lies in finding a remedy for lack of binary protection vulnerability in Android-based mobile apps. The motivation behind conducting this research on PayPal is because of its widespread popularity, and the reported increase in the attacks targeting Android apps along with the sensitive nature of payment gateway mobile apps. This paper proposes an anti-circumvention security approach called Android Apps Permissions Integrity Verifier (AAPIV) to achieve the desired goal. AAPIV captures and computes the authentic unique 256-bit hash of the AndroidManifest.xml file of a legitimate Android-based mobile app. An app's permissions are registered in AndroidManifest.xml file in its Android Package Kit file. AAPIV stores the computed hash in its cloud-based database server. For every access request to the data stored in the database server of the mobile app service provider, the 256-bit hash of the AndroidManifest.xml file of the requesting app is captured, extracted, computed, and verified for authenticity against that stored in AAPIV's cloud-based database server. In case both hashes are identical, this denotes a legitimate access request from an authentic mobile app, and accordingly the access request is allowed, otherwise the access request is denied. An experimental security evaluation was applied on PayPal Android-based payment gateway mobile app. It demonstrated that AAPIV effectively achieved its intended objective.

DOI

10.21608/ijci.2024.277929.1156

Keywords

Android-Based Apps Security, Mobile Apps Permissions, Integrity Attacks, Android Package Kit

Authors

First Name

Omar

Last Name

Hussein

MiddleName

-

Affiliation

Department of Management Information Systems, Faculty of Management Sciences, October University for Modern Sciences and Arts (MSA)

Email

ohusseins@gmail.com

City

-

Orcid

-

Volume

11

Article Issue

2

Related Issue

48570

Issue Date

2024-07-01

Receive Date

2024-03-19

Publish Date

2024-06-01

Page Start

25

Page End

43

Print ISSN

1687-7853

Online ISSN

2735-3257

Link

https://ijci.journals.ekb.eg/article_356933.html

Detail API

https://ijci.journals.ekb.eg/service?article_code=356933

Order

4

Type

Original Article

Type Code

877

Publication Type

Journal

Publication Title

IJCI. International Journal of Computers and Information

Publication Link

https://ijci.journals.ekb.eg/

MainTitle

Detection of Integrity Attacks on Permissions of Android-Based Mobile Apps: Security Evaluation on PayPal

Details

Type

Article

Created At

24 Dec 2024