NUST Institutional Repository

Evasion of Google Play Protect Security Mechanisms Through Incremental Malicious Updates

Show simple item record

dc.contributor.author Muhammad, Zia
dc.contributor.author Supervised by Dr. Muhuammad Faisal Amjad.
dc.date.accessioned 2021-04-23T05:32:02Z
dc.date.available 2021-04-23T05:32:02Z
dc.date.issued 2021-02
dc.identifier.other TIS-314
dc.identifier.other MSIS-17
dc.identifier.uri http://10.250.8.41:8080/xmlui/handle/123456789/23796
dc.description.abstract Android is a leading mobile Operating System (OS), and its market share is increasing drastically. Every Android device has a built-in service called Play Store for application distribution and updates. A malicious application distributed through the Google play store may create a privacy breach. In order to protect end-users, an in-depth security mechanism, namely Google Play Protect, has been deployed in the Google Play Store to safeguard Android devices from malicious applications. In this work, we have investigated the malicious application detection capabilities of the Google Play Protect by employing a novel attack based on incremental malicious updates, which circumvents the security afforded by Play Protect. Therefore, a seemingly benign application called Voice Search is designed and deployed on Play Store. The Voice Search application exploits Google Play Store permissions and bypasses users' privacy through malicious updates. After malicious updates are installed, the application collects the required data such as device details, location, contact information and exfiltrates it to the attacker's server. Results show that Google Play Protect is vulnerable to malicious incremental update attacks. en_US
dc.language.iso en en_US
dc.publisher MCS en_US
dc.title Evasion of Google Play Protect Security Mechanisms Through Incremental Malicious Updates en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account