学位论文详细信息
Security Analysis of Secure Virtual Keyboards in Android Mobile Payment Apps
Security Virtual Keyboard;Encryption;Input Taint Tracking;Reverse Engineering;621
공과대학 컴퓨터공학부 ;
University:서울대학교 대학원
关键词: Security Virtual Keyboard;    Encryption;    Input Taint Tracking;    Reverse Engineering;    621;   
Others  :  http://s-space.snu.ac.kr/bitstream/10371/122665/1/000000133866.pdf
美国|英语
来源: Seoul National University Open Repository
PDF
【 摘 要 】

Mobile payment applications typically employ extra security measures due to the sensitivity of information that they handle. This paper investigates the security of secure virtual keyboards which are frequently used in South Korea. Unlike numerous studies on Android apps in the past, analyzing payment apps is particularly challenging as they use obfuscation. To overcome these difficulties, we extend TaintDroid to leverage the user interfaces that keyboards use to interact with others. With the tool, we examine how securely these apps handle encrypted user input through secure virtual keyboards. We find that although these apps encrypt user data through a third-party secure virtual keyboard library to protect against memory dumping attack, all the target apps decrypt all the sensitive information using the decryption APIs of secure virtual keyboard libraries, increasing a vulnerability time window. We conclude the paper with a discussion of possible countermeasures.

【 预 览 】
附件列表
Files Size Format View
Security Analysis of Secure Virtual Keyboards in Android Mobile Payment Apps 1668KB PDF download
  文献评价指标  
  下载次数:18次 浏览次数:15次