(Press-News.org) RIVERSIDE, Calif. — A team of researchers, including an assistant professor at the University of California, Riverside Bourns College of Engineering, have identified a weakness believed to exist in Android, Windows and iOS mobile operating systems that could be used to obtain personal information from unsuspecting users. They demonstrated the hack in an Android phone.
The researchers tested the method and found it was successful between 82 percent and 92 percent of the time on six of the seven popular apps they tested. Among the apps they easily hacked were Gmail, CHASE Bank and H&R Block. Amazon, with a 48 percent success rate, was the only app they tested that was difficult to penetrate.
The paper, "Peeking into Your App without Actually Seeing It: UI State Inference and Novel Android Attacks," will be presented Friday, Aug. 22 at the 23rd USENIX Security Symposium in San Diego. Authors of the paper are Zhiyun Qian, of the Computer Science and Engineering Department at UC Riverside; Z. Morley Mao, an associate professor at the University of Michigan; and Qi Alfred Chen, a Ph.D. student working with Mao.
The researchers believe their method will work on other operating systems because they share a key feature researchers exploited in the Android system. However, they haven't tested the program using the other systems.
The researchers started working on the method because they believed there was a security risk with so many apps being created by some many developers. Once a user downloads a bunch of apps to his or her smart phone they are all running on the same shared infrastructure, or operating system.
"The assumption has always been that these apps can't interfere with each other easily," Qian said. "We show that assumption is not correct and one app can in fact significantly impact another and result in harmful consequences for the user."
The attack works by getting a user to download a seemingly benign, but actually malicious, app, such as one for background wallpaper on a phone. Once that app is installed, the researchers are able to exploit a newly discovered public side channel — the shared memory statistics of a process, which can be accessed without any privileges. (Shared memory is a common operating system feature to efficiently allow processes share data.)
The researchers monitor changes in shared memory and are able to correlate changes to what they call an "activity transition event," which includes such things as a user logging into Gmail or H&R Block or a user taking a picture of a check so it can be deposited online, without going to a physical CHASE Bank. Augmented with a few other side channels, the authors show that it is possible to fairly accurately track in real time which activity a victim app is in.
There are two keys to the attack. One, the attack needs to take place at the exact moment the user is logging into the app or taking the picture. Two, the attack needs to be done in an inconspicuous way. The researchers did this by carefully calculating the attack timing.
"By design, Android allows apps to be preempted or hijacked," Qian said. "But the thing is you have to do it at the right time so the user doesn't notice. We do that and that's what makes our attack unique."
The researchers created three short videos that show how the attacks work. They can be viewed here: http://bit.ly/1ByiCd3.
Here is a list of the seven apps the researchers attempted to attack and their success rates: Gmail (92 percent), H&R Block (92 percent), Newegg (86 percent), WebMD (85 percent), CHASE Bank (83 percent), Hotels.com (83 percent) and Amazon (48 percent).
Amazon was more difficult to attack because its app allows one activity to transition to almost any other activity, increasing the difficulty of guessing which activity it is currently in.
Asked what a smart phone user can do about this situation, Qian said, "Don't install untrusted apps." On the operating system design, a more careful tradeoff between security and functionality needs to be made in the future, he said. For example, side channels need to be eliminated or more explicitly regulated.
INFORMATION:
Hacking Gmail with 92 percent success
UC Riverside assistant professor is among group that develops novel method to attack apps on Android, and likely other, operating systems
2014-08-21
ELSE PRESS RELEASES FROM THIS DATE:
Researchers identify potential risk factors for urinary tract infections in young girls
2014-08-21
Winston-Salem, N.C. – August, 21, 2014 – Young girls with an intense, red, itchy rash on their outer genital organs may be at increased risk of developing urinary tract infections (UTIs), according to new research from Wake Forest Baptist Medical Center. The treatment may be as simple as better hygiene and avoiding potential irritants such as bubble baths and swimming pools.
"Vulvitis is a common condition affecting women and girls of all ages," said senior author Steve J. Hodges, M.D., associate professor of urology at Wake Forest Baptist. "We found that girls with ...
Difficulty assessing effort drives motivation deficits in schizophrenia, study finds
2014-08-21
SAN FRANCISCO, Aug. 21, 2014 – Individuals with schizophrenia often have trouble engaging in daily tasks or setting goals for themselves, and a new study from San Francisco State University suggests the reason might be their difficulty in assessing the amount of effort required to complete tasks.
The research, detailed in an article published this week in the Journal of Abnormal Psychology, can assist health professionals in countering motivation deficits among patients with schizophrenia and help those patients function normally by breaking up larger, complex tasks into ...
A NASA satellite double-take at Hurricane Lowell
2014-08-21
Lowell is now a large hurricane in the Eastern Pacific and NASA's Aqua and Terra satellites double-teamed it to provide infrared and radar data to scientists. Lowell strengthened into a hurricane during the morning hours of August 21.
When NASA's Aqua satellite passed over Lowell on August 20 at 21:05 UTC (4:05 p.m. EDT), the Atmospheric Infrared Sounder got an infrared look at Lowell's cloud top temperatures when it was still a tropical storm. AIRS showed a very thick band of thunderstorms surrounding the center of circulation and what appeared to be a very small cloud-free ...
Researchers examine impact of race and ethnicity in motor complete spinal cord injury
2014-08-21
West Orange, NJ. August 21, 2014. Researchers have published a study examining racial and ethnic influences in the outcomes of patients with motor complete spinal cord injury (SCI). The article, "Racial and ethnic disparities in functioning at discharge and follow-up among patients with motor complete SCI," was published online ahead of print on August 2 by the Archives of Physical Medicine & Rehabilitation (doi: 10.1016/j.apmr.2014.07.398). Findings included small but significant differences in self-care and mobility at discharge; no differences were apparent at 1-year ...
Reading 'Fifty Shades' linked to unhealthy behaviors
2014-08-21
EAST LANSING, Mich. --- Young adult women who read "Fifty Shades of Grey" are more likely than nonreaders to exhibit signs of eating disorders and have a verbally abusive partner, finds a new study led by a Michigan State University researcher.
Further, women who read all three books in the blockbuster "Fifty Shades" erotic romance series are at increased risk of engaging in binge drinking and having multiple sex partners.
All are known risks associated with being in an abusive relationship, much like the lead character, Anastasia, is in "Fifty Shades," said Amy Bonomi, ...
Yale's cool molecules
2014-08-21
New Haven, Conn. – It's official. Yale physicists have chilled the world's coolest molecules.
The tiny titans in question are bits of strontium monofluoride, dropped to 2.5 thousandths of a degree above absolute zero through a laser cooling and isolating process called magneto-optical trapping (MOT). They are the coldest molecules ever achieved through direct cooling, and they represent a physics milestone likely to prompt new research in areas ranging from quantum chemistry to tests of the most basic theories in particle physics.
"We can start studying chemical reactions ...
Influenced by self-interest, humans less concerned about inequity to others
2014-08-21
ATLANTA—Strongly influenced by their self-interest, humans do not protest being overcompensated, even when there are no consequences, researchers in Georgia State University's Brains and Behavior Program have found.
This could imply that humans are less concerned than previously believed about the inequity of others, researchers said. Their findings are published in the journal Brain Connectivity. These findings suggest humans' sense of unfairness is affected by their self-interest, indicating the interest humans show in others' outcomes is a recently evolved propensity.
It ...
Women's health and Fifty Shades: Increased risks for young adult readers?
2014-08-21
New Rochelle, NY, August 21, 2014—Popular fiction that normalizes and glamorizes violence against women, such as the blockbuster Fifty Shades series, may be associated with a greater risk of potentially harmful health behaviors and risks. The results of a provocative new study are presented in the article "Fiction or Not? Fifty Shades Is Associated with Health Risks in Adolescent and Young Adult Females," published in Journal of Women's Health, a peer-reviewed publication from Mary Ann Liebert, Inc., publishers. The article is available free on the Journal of Women's Health ...
AAAS: Sri Lanka images show no significant increase in public facilities, despite promises
2014-08-21
Thousands of Sri Lankans remain refugees five years after a long civil war, and satellite-image analysis seems to reveal many new housing-like structures and development in a military zone in the northern part of the country. However, the analysis also shows no significant increase in civic facilities despite government claims that it has seized the land for public use.
The analysis, completed by the nonprofit, nonpartisan American Association for the Advancement of Science (AAAS), suggests a sharp increase in the number of residential housing-type structures within the ...
Research offers insight into cellular biology of colorectal cancer
2014-08-21
LAWRENCE — A study recently published in the journal Carcinogenesis by researchers at the University of Kansas shows a new role for the protein adenomatous polyposis coli (APC) in suppressing colorectal cancer — the second-leading cause of cancer-related deaths in the U.S.
Lead author Kristi Neufeld, associate professor in the Department of Molecular Biosciences and co-leader of the Cancer Biology program at the KU Cancer Center, has spent the better part of her career trying to understand the various activities of APC, a protein whose functional loss is thought to initiate ...
LAST 30 PRESS RELEASES:
Scalable and healable gradient textiles for multi‑scenario radiative cooling via bicomponent blow spinning
Research shows informed traders never let a good climate crisis go to waste
Intelligent XGBoost framework enhances asphalt pavement skid resistance assessment
Dual-function biomaterials for postoperative osteosarcoma: Tumor suppression and bone regeneration
New framework reveals where transport emissions concentrate in Singapore
NTP-enhanced lattice oxygen activation in Ce-Co catalysts for low-temperature soot combustion
Synergistic interface engineering in Cu-Zn-Ce catalysts for efficient CO2 hydrogenation to methanol
COVID-19 leaves a lasting mark on the human brain
Scientists use ultrasound to soften and treat cancer tumors without damaging healthy tissue
Community swimming program for Black youth boosts skills, sense of belonging, study finds
Specific depressive symptoms in midlife linked to increased dementia risk
An ‘illuminating’ design sheds light on cholesterol
Who is more likely to get long COVID?
Study showcases resilience and rapid growth of “living rocks”
Naval Research Lab diver earns Office of Naval Research 2025 Sailor of the Year
New Mayo-led study establishes practical definition for rapidly progressive dementia
Fossil fuel industry’s “climate false solutions” reinforce its power and aggravate environmental injustice
Researchers reveal bias in a widely used measure of algorithm performance
Alcohol causes cancer. A study from IOCB Prague confirms damage to DNA and shows how cells defend against it
Hidden viruses in wastewater treatment may shape public health risks, study finds
Unlock the power of nature: how biomass can transform climate mitigation
Biochar reshapes hidden soil microbes that capture carbon dioxide in farmland
Reducing saturated fat intake shows mortality benefit, but only in high-risk individuals
Manta rays create mobile ecosystems, study finds
Study: Mixed results in using lipoic acid to treat progressive multiple sclerosis
Norbert Holtkamp appointed director of Fermi National Accelerator Laboratory
New agentic AI platform accelerates advanced optics design
Biologists discover neurons use physical signals — not electricity — to stabilize communication
Researchers discover that a hormone can access the brain by hitchhiking
University of Oklahoma researcher awarded funding to pursue AI-powered material design
[Press-News.org] Hacking Gmail with 92 percent successUC Riverside assistant professor is among group that develops novel method to attack apps on Android, and likely other, operating systems








