(Press-News.org) In secrecy, the "apps" forward private data to a third party. Computer scientists from Saarbrücken have developed a new approach to prevent this data abuse. They can put a stop to the data theft through the app "SRT AppGuard". The chief attraction: For the protection to work, it is not necessary to identify the suspicious programs in advance, nor must the operating system be changed. Instead, the freely available app attacks the program code of the digital spies.
"My smartphone knows everything about me, starting with my name, my phone number, my e-mail address, my interests, up to my current location," explains computer science professor Michael Backes, who manages the Center for IT-Security, Privacy and Accountability at Saarland University. "It even knows my friends quite well, as it saves their contact details, too," says Backes. Therefore he is not surprised that several mobile applications, also known as apps, display simple functionality up front, while in the background, they send the identification number of the device, the personal whereabouts of the user, or even the contact details of friends, colleagues and customers to a server somewhere in the internet.
The producers of anti-virus software have been making vivid predictions of such scenarios for some time now; in the meantime, scientific studies also prove the threat. A study from the University of California in Santa Barbara (US) concluded that among 825 examined apps for the iPhone and its operating system iOS, 21 percent forward the ID number, four percent the current position, and 0.5 percent even copy the address book.
Michael Backes and his team of researchers now bring this abuse to an end. Their approach focuses on Android. It is the most common operating system for smartphones and tablet computers. Developed by the Google software group, this freely available operating system is used by several mobile phone manufacturers, and since November 2011 is activated daily on more than 700,000 devices.
However, Android is known for its rigorous policy on assignment of privileges. If a user wants to install a downloaded app, he learns via a list which access rights to data (location, contacts, photos) and functions (Internet, locating) will be claimed by that app. Now he has two options: Either he accepts all conditions, or the app will not be installed. After the installation, the privileges cannot be revoked. "Moreover, many developers generally claim all rights for their app because the concept of privileges of Android is misleading, but they want to ensure the smooth functioning of their app nevertheless," explains Philipp von Styp-Rekowsky, PhD student at the chair in IT security and cryptography.
This "sink-or-swim" strategy is put to rest by the researcher from Saarbrücken. The app "SRT AppGuard" based on their approach determines, for every application installed on a smartphone, what it accesses, and shows this information to the user. Privileges can now be revoked or granted to the respective app at any time. The researchers have already published the app on the platform "Google Play". It can be downloaded there for free. It runs problem-free on Android 3.x.x and higher. The development of the app has been taken on by the enterprise Backes SRT, which was founded by Backes in 2010. It is also located on the campus in Saarbrücken.
Computer Science on the Saarland University Campus
Apart from the Saarland University chair in computer science and the Center for IT-Security, Privacy and Accountability, the German Research Center for Artificial Intelligence, the Max Planck Institute for Computer Science, the Max Planck Institute for Software Systems, the Center for Bioinformatics, the Intel Visual Computing Institute and the Cluster of Excellence on "Multimodal Computing and Interaction" can also be found there.
Technical background
For their approach, the Saarbrücken researchers use the fact that the Android apps work in a so-called virtual machine, which is written in the computer language Java. Therefore the apps are saved on the smartphone as executable "bytecode" after installation. That's when SRT AppGuard comes into play. While the suspicious app is running, it is checking its bytecode for the security-sensitive instructions, which it had been programmed to do by the experts from Saarbrücken. It adds a special control code in front of the suspect comment or procedure. This is only necessary once, as the secured bytecode replaces the original one afterwards. This overwriting process usually only takes a few seconds and a small number of lines of additional code. The computer scientists have reviewed 13 apps, among them the popular game "Angry Birds", the music identifying app "Shazam" and the social-media apps "Facebook" and "What's app". For the app belonging to the microblogging service Twitter, for example, it needs 16.7 seconds and 48 additional lines of code. "It is just as in an art museum ," explains Styp-Rekoswky, "Instead of checking every visitor, you only provide the most valuable paintings with an invisible alarm function."
But the Saarbrücken app can do even more than just providing alerts. It is also able to block suspicious requests or change them so they cannot do any harm. "Thus, we can also prevent the use of known security vulnerabilities of the respective apps or Android operating system," adds Professor Michael Backes. This possibility is very important if the manufacturer cannot provide security fixes in time," says the professor.
INFORMATION:
See also:
The App on Google Play Store
https://play.google.com/store/apps/details?id=com.srt.appguard.mobile
Michael Backes, Sebastian Gerling, Christian Hammer, Matteo Maffei and Philipp von Styp-Rekowsky: The Android Monitor – Real-time policy enforcement for third-party applications
http://www.infsec.cs.uni-saarland.de/projects/android-monitor/android-monitor.pdf
Center for IT-Security, Privacy and Accountability (CISPA)
www.cispa-security.de
For further information please contact:
Professor Dr. Michael Backes
Chair CISPA
Phone: +49 681 302-3259
E-Mail: backes@cispa.uni-saarland.de
Sebastian Gerling
Administrative manager CISPA
Phone: +49 681 302-57373
E-Mail: sgerling@cispa.uni-saarland.de
Editing:
Gordon Bolduan
Scientific Communicator
Phone: +49 681 302-70741
E-Mail: gbolduan@mmci.uni-saarland.de
END
The earth is shaken daily by strong earthquakes recorded by a number of seismic stations worldwide. Tectonic tremor, however, is a new type of seismic signal that seismologist started studying only within the last few years. Tremor is less hazardous than earthquakes and occurs at greater depth. The link between tremor and earthquakes may provide clues about the more destructive earthquakes that occur at shallower depths. Geophysicists of Karlsruhe Institute of Technology (KIT) collected seismic data of tectonic tremor in California. These data are now being evaluated in ...
The immunosuppressive drug fingolimod (trade name: Gilenya®) is approved for the treatment of highly-active relapsing-remitting multiple sclerosis (RRMS) in adults. In an early benefit assessment pursuant to "Act on the Reform of the Market for Medicinal Products" (AMNOG), the German Institute for Quality and Efficiency in Health Care (IQWiG) assessed whether fingolimod offers an added benefit compared with the present standard therapy.
According to the findings of the assessment, patients with a rapidly progressive and severe course of disease who take fingolimod experience ...
Over the past year, some news reports have questioned the long-term viability and popularity of daily deal companies, but the industry shows no evidence of slowing down, according to a new study from Rice University.
In the study, "How Businesses Fare With Daily Deals As They Gain Experience: A Multi-Time Period Study of Daily Deal Performance," Utpal Dholakia examines performance of daily deals using survey data from 641 small- and medium-sized businesses obtained at three time periods: April-May 2011, October 2011, and May 2012. Dholakia is a professor of management ...
Around seven percent of adults suffer from an intolerance to wine. This is the result of a survey presented by Peter Wigand and co-authors in the current edition of Deutsches Ärzteblatt International (Dtsch Arztelb Int 2012; 109 (25): 437-44).
The authors evaluated 948 questionnaires that were returned from the 4000 sent out to randomly selected people between the ages of 20 and 69 years. They found that women (8.9%) were more often affected by an intolerance to wine than men (5.2%). The most commonly reported reactions included flushed and itchy skin and a runny nose. ...
EAST LANSING, Mich. — The stock market should be regulated only during times of extraordinary financial disruptions when speculators can destroy healthy businesses, according to a new study led by a Michigan State University scholar.
The study, in the Journal of Financial Economics, is one of the first to suggest when the U.S. Securities and Exchange Commission should get involved in the market.
The answer: rarely. The SEC should step in only when outside financial disruptions make it impossible for large shareholders to fend off "short sellers" – or speculators betting ...
Does being an intense mother make women unhappy? According to a new study by Kathryn Rizzo and colleagues, from the University of Mary Washington in the US, women who believe in intensive parenting - i.e., that women are better parents than men, that mothering should be child-centred, and that children should be considered sacred and are fulfilling to parents - are more likely to have negative mental health outcomes. The work is published online in Springer's Journal of Child and Family Studies.
Parenting can be quite challenging and requires wide-ranging skills and expertise ...
Using piezoelectric materials, researchers have replicated the muscle motion of the human eye to control camera systems in a way designed to improve the operation of robots. This new muscle-like action could help make robotic tools safer and more effective for MRI-guided surgery and robotic rehabilitation.
Key to the new control system is a piezoelectric cellular actuator that uses a novel biologically inspired technology that will allow a robot eye to move more like a real eye. This will be useful for research studies on human eye movement as well as making video feeds ...
When evaluating job applicants, employers want to be sure that they choose the right person for the job. Many employers, from consulting firms to federal agencies, will ask prospective employees to complete extensive tests and questionnaires to get a better sense of what those employees might be like in an office setting. But new research published in the July 2012 issue of Perspectives on Psychological Science, a journal of the Association for Psychological Science, suggests that a different factor – employee interests – may be a better way to predict who will perform ...
Obesity increases the risk of acute kidney injury (AKI) following cardiac surgery, according to a Vanderbilt study published in the Journal of the American Society of Nephrology.
Considered common after cardiac surgery, AKI represents a fivefold increase in mortality risk within 30 days after the procedure and is associated with longer hospital stays and a range of complications.
The study, led by anesthesiologist Frederic T. (Josh) Billings IV, M.D., M.Sc., followed a sample of 455 cardiac surgery patients at Vanderbilt University Hospital and Brigham and Women's Hospital ...
MANHATTAN, Kan. -- Many patients seem to ignore prescription drug warning labels with instructions that are critical for safe and effective use, according to a study by a Kansas State University researcher working with scientists at Michigan State University.
Consumers, particularly older ones, often overlook prescription drug warning labels in part because the labels fail to attract attention, said Nora Bello, an assistant professor of statistics at Kansas State University. Bello helped investigate the effectiveness of prescription drug warning labels to convey drug ...