(Press-News.org) RIVERSIDE, Calif. — A team of researchers, including an assistant professor at the University of California, Riverside Bourns College of Engineering, have identified a weakness believed to exist in Android, Windows and iOS mobile operating systems that could be used to obtain personal information from unsuspecting users. They demonstrated the hack in an Android phone.
The researchers tested the method and found it was successful between 82 percent and 92 percent of the time on six of the seven popular apps they tested. Among the apps they easily hacked were Gmail, CHASE Bank and H&R Block. Amazon, with a 48 percent success rate, was the only app they tested that was difficult to penetrate.
The paper, "Peeking into Your App without Actually Seeing It: UI State Inference and Novel Android Attacks," will be presented Friday, Aug. 22 at the 23rd USENIX Security Symposium in San Diego. Authors of the paper are Zhiyun Qian, of the Computer Science and Engineering Department at UC Riverside; Z. Morley Mao, an associate professor at the University of Michigan; and Qi Alfred Chen, a Ph.D. student working with Mao.
The researchers believe their method will work on other operating systems because they share a key feature researchers exploited in the Android system. However, they haven't tested the program using the other systems.
The researchers started working on the method because they believed there was a security risk with so many apps being created by some many developers. Once a user downloads a bunch of apps to his or her smart phone they are all running on the same shared infrastructure, or operating system.
"The assumption has always been that these apps can't interfere with each other easily," Qian said. "We show that assumption is not correct and one app can in fact significantly impact another and result in harmful consequences for the user."
The attack works by getting a user to download a seemingly benign, but actually malicious, app, such as one for background wallpaper on a phone. Once that app is installed, the researchers are able to exploit a newly discovered public side channel — the shared memory statistics of a process, which can be accessed without any privileges. (Shared memory is a common operating system feature to efficiently allow processes share data.)
The researchers monitor changes in shared memory and are able to correlate changes to what they call an "activity transition event," which includes such things as a user logging into Gmail or H&R Block or a user taking a picture of a check so it can be deposited online, without going to a physical CHASE Bank. Augmented with a few other side channels, the authors show that it is possible to fairly accurately track in real time which activity a victim app is in.
There are two keys to the attack. One, the attack needs to take place at the exact moment the user is logging into the app or taking the picture. Two, the attack needs to be done in an inconspicuous way. The researchers did this by carefully calculating the attack timing.
"By design, Android allows apps to be preempted or hijacked," Qian said. "But the thing is you have to do it at the right time so the user doesn't notice. We do that and that's what makes our attack unique."
The researchers created three short videos that show how the attacks work. They can be viewed here: http://bit.ly/1ByiCd3.
Here is a list of the seven apps the researchers attempted to attack and their success rates: Gmail (92 percent), H&R Block (92 percent), Newegg (86 percent), WebMD (85 percent), CHASE Bank (83 percent), Hotels.com (83 percent) and Amazon (48 percent).
Amazon was more difficult to attack because its app allows one activity to transition to almost any other activity, increasing the difficulty of guessing which activity it is currently in.
Asked what a smart phone user can do about this situation, Qian said, "Don't install untrusted apps." On the operating system design, a more careful tradeoff between security and functionality needs to be made in the future, he said. For example, side channels need to be eliminated or more explicitly regulated.
INFORMATION:
Hacking Gmail with 92 percent success
UC Riverside assistant professor is among group that develops novel method to attack apps on Android, and likely other, operating systems
2014-08-21
ELSE PRESS RELEASES FROM THIS DATE:
Researchers identify potential risk factors for urinary tract infections in young girls
2014-08-21
Winston-Salem, N.C. – August, 21, 2014 – Young girls with an intense, red, itchy rash on their outer genital organs may be at increased risk of developing urinary tract infections (UTIs), according to new research from Wake Forest Baptist Medical Center. The treatment may be as simple as better hygiene and avoiding potential irritants such as bubble baths and swimming pools.
"Vulvitis is a common condition affecting women and girls of all ages," said senior author Steve J. Hodges, M.D., associate professor of urology at Wake Forest Baptist. "We found that girls with ...
Difficulty assessing effort drives motivation deficits in schizophrenia, study finds
2014-08-21
SAN FRANCISCO, Aug. 21, 2014 – Individuals with schizophrenia often have trouble engaging in daily tasks or setting goals for themselves, and a new study from San Francisco State University suggests the reason might be their difficulty in assessing the amount of effort required to complete tasks.
The research, detailed in an article published this week in the Journal of Abnormal Psychology, can assist health professionals in countering motivation deficits among patients with schizophrenia and help those patients function normally by breaking up larger, complex tasks into ...
A NASA satellite double-take at Hurricane Lowell
2014-08-21
Lowell is now a large hurricane in the Eastern Pacific and NASA's Aqua and Terra satellites double-teamed it to provide infrared and radar data to scientists. Lowell strengthened into a hurricane during the morning hours of August 21.
When NASA's Aqua satellite passed over Lowell on August 20 at 21:05 UTC (4:05 p.m. EDT), the Atmospheric Infrared Sounder got an infrared look at Lowell's cloud top temperatures when it was still a tropical storm. AIRS showed a very thick band of thunderstorms surrounding the center of circulation and what appeared to be a very small cloud-free ...
Researchers examine impact of race and ethnicity in motor complete spinal cord injury
2014-08-21
West Orange, NJ. August 21, 2014. Researchers have published a study examining racial and ethnic influences in the outcomes of patients with motor complete spinal cord injury (SCI). The article, "Racial and ethnic disparities in functioning at discharge and follow-up among patients with motor complete SCI," was published online ahead of print on August 2 by the Archives of Physical Medicine & Rehabilitation (doi: 10.1016/j.apmr.2014.07.398). Findings included small but significant differences in self-care and mobility at discharge; no differences were apparent at 1-year ...
Reading 'Fifty Shades' linked to unhealthy behaviors
2014-08-21
EAST LANSING, Mich. --- Young adult women who read "Fifty Shades of Grey" are more likely than nonreaders to exhibit signs of eating disorders and have a verbally abusive partner, finds a new study led by a Michigan State University researcher.
Further, women who read all three books in the blockbuster "Fifty Shades" erotic romance series are at increased risk of engaging in binge drinking and having multiple sex partners.
All are known risks associated with being in an abusive relationship, much like the lead character, Anastasia, is in "Fifty Shades," said Amy Bonomi, ...
Yale's cool molecules
2014-08-21
New Haven, Conn. – It's official. Yale physicists have chilled the world's coolest molecules.
The tiny titans in question are bits of strontium monofluoride, dropped to 2.5 thousandths of a degree above absolute zero through a laser cooling and isolating process called magneto-optical trapping (MOT). They are the coldest molecules ever achieved through direct cooling, and they represent a physics milestone likely to prompt new research in areas ranging from quantum chemistry to tests of the most basic theories in particle physics.
"We can start studying chemical reactions ...
Influenced by self-interest, humans less concerned about inequity to others
2014-08-21
ATLANTA—Strongly influenced by their self-interest, humans do not protest being overcompensated, even when there are no consequences, researchers in Georgia State University's Brains and Behavior Program have found.
This could imply that humans are less concerned than previously believed about the inequity of others, researchers said. Their findings are published in the journal Brain Connectivity. These findings suggest humans' sense of unfairness is affected by their self-interest, indicating the interest humans show in others' outcomes is a recently evolved propensity.
It ...
Women's health and Fifty Shades: Increased risks for young adult readers?
2014-08-21
New Rochelle, NY, August 21, 2014—Popular fiction that normalizes and glamorizes violence against women, such as the blockbuster Fifty Shades series, may be associated with a greater risk of potentially harmful health behaviors and risks. The results of a provocative new study are presented in the article "Fiction or Not? Fifty Shades Is Associated with Health Risks in Adolescent and Young Adult Females," published in Journal of Women's Health, a peer-reviewed publication from Mary Ann Liebert, Inc., publishers. The article is available free on the Journal of Women's Health ...
AAAS: Sri Lanka images show no significant increase in public facilities, despite promises
2014-08-21
Thousands of Sri Lankans remain refugees five years after a long civil war, and satellite-image analysis seems to reveal many new housing-like structures and development in a military zone in the northern part of the country. However, the analysis also shows no significant increase in civic facilities despite government claims that it has seized the land for public use.
The analysis, completed by the nonprofit, nonpartisan American Association for the Advancement of Science (AAAS), suggests a sharp increase in the number of residential housing-type structures within the ...
Research offers insight into cellular biology of colorectal cancer
2014-08-21
LAWRENCE — A study recently published in the journal Carcinogenesis by researchers at the University of Kansas shows a new role for the protein adenomatous polyposis coli (APC) in suppressing colorectal cancer — the second-leading cause of cancer-related deaths in the U.S.
Lead author Kristi Neufeld, associate professor in the Department of Molecular Biosciences and co-leader of the Cancer Biology program at the KU Cancer Center, has spent the better part of her career trying to understand the various activities of APC, a protein whose functional loss is thought to initiate ...
LAST 30 PRESS RELEASES:
2025 Gut Microbiota for Health World Summit to spotlight groundbreaking research
International survey finds that support for climate interventions is tied to being hopeful and worried about climate change
Cambridge scientist launches free VR platform that eliminates the fear of public speaking
Open-Source AI matches top proprietary model in solving tough medical cases
Good fences make good neighbors (with carnivores)
NRG Oncology trial supports radiotherapy alone following radical hysterectomy should remain the standard of care for early-stage, intermediate-risk cervical cancer
Introducing our new cohort of AGA Future Leaders
Sharks are dying at alarming rates, mostly due to fishing. Retention bans may help
Engineering excellence: Engineers with ONR ties elected to renowned scientific academy
New CRISPR-based diagnostic test detects pathogens in blood without amplification
Immunotherapy may boost KRAS-targeted therapy in pancreatic cancer
Growing solar: Optimizing agrivoltaic systems for crops and clean energy
Scientists discover how to reactivate cancer’s molecular “kill switch”
YouTube influencers: gaming’s best friend or worst enemy?
uOttawa scientists use light to unlock secret of atoms
NJIT mathematician to help map Earth's last frontier with Navy grant
NASA atmospheric wave-studying mission releases data from first 3,000 orbits
‘Microlightning’ in water droplets may have sparked life on Earth
Smoke from wildland-urban interface fires more deadly than remote wildfires
What’s your body really worth? New AI model reveals your true biological age from 5 drops of blood
Protein accidentally lassos itself, helping explain unusual refolding behavior
With bird flu in raw milk, many in U.S. still do not know risks of consuming it
University of Minnesota research team awarded $3.8 million grant to develop cell therapy to combat Alzheimer’s disease
UConn uncovers new clue on what is leading to neurodegenerative diseases like Alzheimer’s and ALS
Resuscitation in out-of-hospital cardiac arrest – it’s how quickly it is done, rather than who does it
A closer look at biomolecular ‘silly putty’
Oxytocin system of breastfeeding affected in mothers with postnatal depression
Liquid metal-enabled synergetic cooling and charging: a leap forward for electric vehicles
Defensive firearm use is far less common than exposure to gun violence
Lifetime and past-year defensive gun use
[Press-News.org] Hacking Gmail with 92 percent successUC Riverside assistant professor is among group that develops novel method to attack apps on Android, and likely other, operating systems