(Press-News.org) RIVERSIDE, Calif. — A team of researchers, including an assistant professor at the University of California, Riverside Bourns College of Engineering, have identified a weakness believed to exist in Android, Windows and iOS mobile operating systems that could be used to obtain personal information from unsuspecting users. They demonstrated the hack in an Android phone.
The researchers tested the method and found it was successful between 82 percent and 92 percent of the time on six of the seven popular apps they tested. Among the apps they easily hacked were Gmail, CHASE Bank and H&R Block. Amazon, with a 48 percent success rate, was the only app they tested that was difficult to penetrate.
The paper, "Peeking into Your App without Actually Seeing It: UI State Inference and Novel Android Attacks," will be presented Friday, Aug. 22 at the 23rd USENIX Security Symposium in San Diego. Authors of the paper are Zhiyun Qian, of the Computer Science and Engineering Department at UC Riverside; Z. Morley Mao, an associate professor at the University of Michigan; and Qi Alfred Chen, a Ph.D. student working with Mao.
The researchers believe their method will work on other operating systems because they share a key feature researchers exploited in the Android system. However, they haven't tested the program using the other systems.
The researchers started working on the method because they believed there was a security risk with so many apps being created by some many developers. Once a user downloads a bunch of apps to his or her smart phone they are all running on the same shared infrastructure, or operating system.
"The assumption has always been that these apps can't interfere with each other easily," Qian said. "We show that assumption is not correct and one app can in fact significantly impact another and result in harmful consequences for the user."
The attack works by getting a user to download a seemingly benign, but actually malicious, app, such as one for background wallpaper on a phone. Once that app is installed, the researchers are able to exploit a newly discovered public side channel — the shared memory statistics of a process, which can be accessed without any privileges. (Shared memory is a common operating system feature to efficiently allow processes share data.)
The researchers monitor changes in shared memory and are able to correlate changes to what they call an "activity transition event," which includes such things as a user logging into Gmail or H&R Block or a user taking a picture of a check so it can be deposited online, without going to a physical CHASE Bank. Augmented with a few other side channels, the authors show that it is possible to fairly accurately track in real time which activity a victim app is in.
There are two keys to the attack. One, the attack needs to take place at the exact moment the user is logging into the app or taking the picture. Two, the attack needs to be done in an inconspicuous way. The researchers did this by carefully calculating the attack timing.
"By design, Android allows apps to be preempted or hijacked," Qian said. "But the thing is you have to do it at the right time so the user doesn't notice. We do that and that's what makes our attack unique."
The researchers created three short videos that show how the attacks work. They can be viewed here: http://bit.ly/1ByiCd3.
Here is a list of the seven apps the researchers attempted to attack and their success rates: Gmail (92 percent), H&R Block (92 percent), Newegg (86 percent), WebMD (85 percent), CHASE Bank (83 percent), Hotels.com (83 percent) and Amazon (48 percent).
Amazon was more difficult to attack because its app allows one activity to transition to almost any other activity, increasing the difficulty of guessing which activity it is currently in.
Asked what a smart phone user can do about this situation, Qian said, "Don't install untrusted apps." On the operating system design, a more careful tradeoff between security and functionality needs to be made in the future, he said. For example, side channels need to be eliminated or more explicitly regulated.
INFORMATION:
Hacking Gmail with 92 percent success
UC Riverside assistant professor is among group that develops novel method to attack apps on Android, and likely other, operating systems
2014-08-21
ELSE PRESS RELEASES FROM THIS DATE:
Researchers identify potential risk factors for urinary tract infections in young girls
2014-08-21
Winston-Salem, N.C. – August, 21, 2014 – Young girls with an intense, red, itchy rash on their outer genital organs may be at increased risk of developing urinary tract infections (UTIs), according to new research from Wake Forest Baptist Medical Center. The treatment may be as simple as better hygiene and avoiding potential irritants such as bubble baths and swimming pools.
"Vulvitis is a common condition affecting women and girls of all ages," said senior author Steve J. Hodges, M.D., associate professor of urology at Wake Forest Baptist. "We found that girls with ...
Difficulty assessing effort drives motivation deficits in schizophrenia, study finds
2014-08-21
SAN FRANCISCO, Aug. 21, 2014 – Individuals with schizophrenia often have trouble engaging in daily tasks or setting goals for themselves, and a new study from San Francisco State University suggests the reason might be their difficulty in assessing the amount of effort required to complete tasks.
The research, detailed in an article published this week in the Journal of Abnormal Psychology, can assist health professionals in countering motivation deficits among patients with schizophrenia and help those patients function normally by breaking up larger, complex tasks into ...
A NASA satellite double-take at Hurricane Lowell
2014-08-21
Lowell is now a large hurricane in the Eastern Pacific and NASA's Aqua and Terra satellites double-teamed it to provide infrared and radar data to scientists. Lowell strengthened into a hurricane during the morning hours of August 21.
When NASA's Aqua satellite passed over Lowell on August 20 at 21:05 UTC (4:05 p.m. EDT), the Atmospheric Infrared Sounder got an infrared look at Lowell's cloud top temperatures when it was still a tropical storm. AIRS showed a very thick band of thunderstorms surrounding the center of circulation and what appeared to be a very small cloud-free ...
Researchers examine impact of race and ethnicity in motor complete spinal cord injury
2014-08-21
West Orange, NJ. August 21, 2014. Researchers have published a study examining racial and ethnic influences in the outcomes of patients with motor complete spinal cord injury (SCI). The article, "Racial and ethnic disparities in functioning at discharge and follow-up among patients with motor complete SCI," was published online ahead of print on August 2 by the Archives of Physical Medicine & Rehabilitation (doi: 10.1016/j.apmr.2014.07.398). Findings included small but significant differences in self-care and mobility at discharge; no differences were apparent at 1-year ...
Reading 'Fifty Shades' linked to unhealthy behaviors
2014-08-21
EAST LANSING, Mich. --- Young adult women who read "Fifty Shades of Grey" are more likely than nonreaders to exhibit signs of eating disorders and have a verbally abusive partner, finds a new study led by a Michigan State University researcher.
Further, women who read all three books in the blockbuster "Fifty Shades" erotic romance series are at increased risk of engaging in binge drinking and having multiple sex partners.
All are known risks associated with being in an abusive relationship, much like the lead character, Anastasia, is in "Fifty Shades," said Amy Bonomi, ...
Yale's cool molecules
2014-08-21
New Haven, Conn. – It's official. Yale physicists have chilled the world's coolest molecules.
The tiny titans in question are bits of strontium monofluoride, dropped to 2.5 thousandths of a degree above absolute zero through a laser cooling and isolating process called magneto-optical trapping (MOT). They are the coldest molecules ever achieved through direct cooling, and they represent a physics milestone likely to prompt new research in areas ranging from quantum chemistry to tests of the most basic theories in particle physics.
"We can start studying chemical reactions ...
Influenced by self-interest, humans less concerned about inequity to others
2014-08-21
ATLANTA—Strongly influenced by their self-interest, humans do not protest being overcompensated, even when there are no consequences, researchers in Georgia State University's Brains and Behavior Program have found.
This could imply that humans are less concerned than previously believed about the inequity of others, researchers said. Their findings are published in the journal Brain Connectivity. These findings suggest humans' sense of unfairness is affected by their self-interest, indicating the interest humans show in others' outcomes is a recently evolved propensity.
It ...
Women's health and Fifty Shades: Increased risks for young adult readers?
2014-08-21
New Rochelle, NY, August 21, 2014—Popular fiction that normalizes and glamorizes violence against women, such as the blockbuster Fifty Shades series, may be associated with a greater risk of potentially harmful health behaviors and risks. The results of a provocative new study are presented in the article "Fiction or Not? Fifty Shades Is Associated with Health Risks in Adolescent and Young Adult Females," published in Journal of Women's Health, a peer-reviewed publication from Mary Ann Liebert, Inc., publishers. The article is available free on the Journal of Women's Health ...
AAAS: Sri Lanka images show no significant increase in public facilities, despite promises
2014-08-21
Thousands of Sri Lankans remain refugees five years after a long civil war, and satellite-image analysis seems to reveal many new housing-like structures and development in a military zone in the northern part of the country. However, the analysis also shows no significant increase in civic facilities despite government claims that it has seized the land for public use.
The analysis, completed by the nonprofit, nonpartisan American Association for the Advancement of Science (AAAS), suggests a sharp increase in the number of residential housing-type structures within the ...
Research offers insight into cellular biology of colorectal cancer
2014-08-21
LAWRENCE — A study recently published in the journal Carcinogenesis by researchers at the University of Kansas shows a new role for the protein adenomatous polyposis coli (APC) in suppressing colorectal cancer — the second-leading cause of cancer-related deaths in the U.S.
Lead author Kristi Neufeld, associate professor in the Department of Molecular Biosciences and co-leader of the Cancer Biology program at the KU Cancer Center, has spent the better part of her career trying to understand the various activities of APC, a protein whose functional loss is thought to initiate ...
LAST 30 PRESS RELEASES:
The puberty talk: Parents split on right age to talk about body changes with kids
Tusi (a mixture of ketamine and other drugs) is on the rise among NYC nightclub attendees
Father’s mental health can impact children for years
Scientists can tell healthy and cancerous cells apart by how they move
Male athletes need higher BMI to define overweight or obesity
How thoughts influence what the eyes see
Unlocking the genetic basis of adaptive evolution: study reveals complex chromosomal rearrangements in a stick insect
Research Spotlight: Using artificial intelligence to reveal the neural dynamics of human conversation
Could opioid laws help curb domestic violence? New USF research says yes
NPS Applied Math Professor Wei Kang named 2025 SIAM Fellow
Scientists identify agent of transformation in protein blobs that morph from liquid to solid
Throwing a ‘spanner in the works’ of our cells’ machinery could help fight cancer, fatty liver disease… and hair loss
Research identifies key enzyme target to fight deadly brain cancers
New study unveils volcanic history and clues to ancient life on Mars
Monell Center study identifies GLP-1 therapies as a possible treatment for rare genetic disorder Bardet-Biedl syndrome
Scientists probe the mystery of Titan’s missing deltas
Q&A: What makes an ‘accidental dictator’ in the workplace?
Lehigh University water scientist Arup K. SenGupta honored with ASCE Freese Award and Lecture
Study highlights gaps in firearm suicide prevention among women
People with medical debt five times more likely to not receive mental health care treatment
Hydronidone for the treatment of liver fibrosis associated with chronic hepatitis B
Rise in claim denial rates for cancer-related advanced genetic testing
Legalizing youth-friendly cannabis edibles and extracts and adolescent cannabis use
Medical debt and forgone mental health care due to cost among adults
Colder temperatures increase gastroenteritis risk in Rohingya refugee camps
Acyclovir-induced nephrotoxicity: Protective potential of N-acetylcysteine
Inhibition of cyclooxygenase-2 upregulates the nuclear factor erythroid 2-related factor 2 signaling pathway to mitigate hepatocyte ferroptosis in chronic liver injury
AERA announces winners of the 2025 Palmer O. Johnson Memorial Award
Mapping minds: The neural fingerprint of team flow dynamics
Patients support AI as radiologist backup in screening mammography
[Press-News.org] Hacking Gmail with 92 percent successUC Riverside assistant professor is among group that develops novel method to attack apps on Android, and likely other, operating systems