{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/49659"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/49659","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Security threats to Android apps","abstract":"Smartphones have become ubiquitous and smartphone users are increasingly relying on the mobile applications (app for short) to store and handle private information. The fluidity of mobile apps and mobile app markets has complicated mobile app security. Many new threats emerged are either because of the deficiency of mobile app development or the design ambiguities of the Android operating system. In order to seek a better understanding of mobile app security, we present a systematic study on security threats to Android apps in two dimensions. First, we study Android apps from mobile health (mHealth for short) sector, in order to understand the prevalence of mobile app threats to that sector. In particular, we present a three-stage study of the mHealth apps to show that mHealth apps make widespread use of unsecured Internet communications and third party servers. Assuming that mobile apps are well protected by their developers, we ask a second question: are there any limitations in fundamental Android security design that can be used by malicious parties to disclose users' sensitive information? We study a newly discovered threat, side-channel information leaks on Android devices, in detail. Particularly, we discover an unexpected channel of information leaks from per-app data usage statistics and demonstrate that a malicious app can infer users' identity or investment information with zero-permission by monitoring the channel. To mitigate these threats, we propose defense strategies for both widespread threats on mHealth apps and the side-channel information leaks on Android devices.","abstract_html":"Smartphones have become ubiquitous and smartphone users are increasingly relying on the mobile applications (app for short) to store and handle private information. The fluidity of mobile apps and mobile app markets has complicated mobile app security. Many new threats emerged are either because of the deficiency of mobile app development or the design ambiguities of the Android operating system. In order to seek a better understanding of mobile app security, we present a systematic study on security threats to Android apps in two dimensions. First, we study Android apps from mobile health (mHealth for short) sector, in order to understand the prevalence of mobile app threats to that sector. In particular, we present a three-stage study of the mHealth apps to show that mHealth apps make widespread use of unsecured Internet communications and third party servers. Assuming that mobile apps are well protected by their developers, we ask a second question: are there any limitations in fundamental Android security design that can be used by malicious parties to disclose users&#x27; sensitive information? We study a newly discovered threat, side-channel information leaks on Android devices, in detail. Particularly, we discover an unexpected channel of information leaks from per-app data usage statistics and demonstrate that a malicious app can infer users&#x27; identity or investment information with zero-permission by monitoring the channel. To mitigate these threats, we propose defense strategies for both widespread threats on mHealth apps and the side-channel information leaks on Android devices.","abstract_has_math":false,"creators":["He, Dongjing"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Gunter, Carl A.","Nahrstedt, Klara"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2014,"date_issued":"2014-05-30T17:03:23Z","date_published":"2014-05-30T17:03:23Z","updated_at":"2026-07-22T22:25:38Z","subjects":["Mobile Security","Mobile Health","Information Leaks"],"languages":["en"],"rights":["Copyright 2014 Dongjing He"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/49659","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Gunter, Carl A.","Nahrstedt, Klara"]},{"key":"dc:creator","label":"Author","values":["He, Dongjing"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2014-05-30T17:03:23Z","2016-09-22T20:59:31Z","2014-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Mobile Security","Mobile Health","Information Leaks"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2014 Dongjing He"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/49659"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Smartphones have become ubiquitous and smartphone users are increasingly relying on the mobile applications (app for short) to store and handle private information. The fluidity of mobile apps and mobile app markets has complicated mobile app security. Many new threats emerged are either because of the deficiency of mobile app development or the design ambiguities of the Android operating system. In order to seek a better understanding of mobile app security, we present a systematic study on security threats to Android apps in two dimensions. First, we study Android apps from mobile health (mHealth for short) sector, in order to understand the prevalence of mobile app threats to that sector. In particular, we present a three-stage study of the mHealth apps to show that mHealth apps make widespread use of unsecured Internet communications and third party servers. Assuming that mobile apps are well protected by their developers, we ask a second question: are there any limitations in fundamental Android security design that can be used by malicious parties to disclose users' sensitive information? We study a newly discovered threat, side-channel information leaks on Android devices, in detail. Particularly, we discover an unexpected channel of information leaks from per-app data usage statistics and demonstrate that a malicious app can infer users' identity or investment information with zero-permission by monitoring the channel. To mitigate these threats, we propose defense strategies for both widespread threats on mHealth apps and the side-channel information leaks on Android devices.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2014-04-29T13:30:31Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 He_Dongjing.pdf: 582486 bytes, checksum: 880dbf8a445fa0a3ed364cfca3e2f15d (MD5) He_Dongjing.pdf: 576002 bytes, checksum: 1db39d80b1b34209546f56feab0a9f07 (MD5)","Made available in DSpace on 2014-05-30T17:03:23Z (GMT). No. of bitstreams: 2 Dongjing_He.pdf: 576002 bytes, checksum: 1db39d80b1b34209546f56feab0a9f07 (MD5) license.txt: 4057 bytes, checksum: 5eeb6c440f558404aecae218e72359ae (MD5)","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (robbins.sd@gmail.com) on 2014-05-30T17:09:19Z Item is restricted until 2016-05-30T17:09:03Z","Restriction data tranferred 2014-07-01T11:38:21-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2016-05-30 12:09:03 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 49710 on 2016-09-22T20:59:31Z."]},{"key":"dc:title","label":"Title","values":["Security threats to Android apps"]}]}],"canonical_facts":{"dc:contributor":["Gunter, Carl A.","Nahrstedt, Klara"],"dc:creator":["He, Dongjing"],"dc:date":["2014-05-30T17:03:23Z","2016-09-22T20:59:31Z","2014-05"],"dc:description":["Smartphones have become ubiquitous and smartphone users are increasingly relying on the mobile applications (app for short) to store and handle private information. The fluidity of mobile apps and mobile app markets has complicated mobile app security. Many new threats emerged are either because of the deficiency of mobile app development or the design ambiguities of the Android operating system. In order to seek a better understanding of mobile app security, we present a systematic study on security threats to Android apps in two dimensions. First, we study Android apps from mobile health (mHealth for short) sector, in order to understand the prevalence of mobile app threats to that sector. In particular, we present a three-stage study of the mHealth apps to show that mHealth apps make widespread use of unsecured Internet communications and third party servers. Assuming that mobile apps are well protected by their developers, we ask a second question: are there any limitations in fundamental Android security design that can be used by malicious parties to disclose users' sensitive information? We study a newly discovered threat, side-channel information leaks on Android devices, in detail. Particularly, we discover an unexpected channel of information leaks from per-app data usage statistics and demonstrate that a malicious app can infer users' identity or investment information with zero-permission by monitoring the channel. To mitigate these threats, we propose defense strategies for both widespread threats on mHealth apps and the side-channel information leaks on Android devices.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2014-04-29T13:30:31Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 He_Dongjing.pdf: 582486 bytes, checksum: 880dbf8a445fa0a3ed364cfca3e2f15d (MD5) He_Dongjing.pdf: 576002 bytes, checksum: 1db39d80b1b34209546f56feab0a9f07 (MD5)","Made available in DSpace on 2014-05-30T17:03:23Z (GMT). No. of bitstreams: 2 Dongjing_He.pdf: 576002 bytes, checksum: 1db39d80b1b34209546f56feab0a9f07 (MD5) license.txt: 4057 bytes, checksum: 5eeb6c440f558404aecae218e72359ae (MD5)","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (robbins.sd@gmail.com) on 2014-05-30T17:09:19Z Item is restricted until 2016-05-30T17:09:03Z","Restriction data tranferred 2014-07-01T11:38:21-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2016-05-30 12:09:03 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 49710 on 2016-09-22T20:59:31Z."],"dc:identifier":["http://hdl.handle.net/2142/49659"],"dc:language":["en"],"dc:rights":["Copyright 2014 Dongjing He"],"dc:subject":["Mobile Security","Mobile Health","Information Leaks"],"dc:title":["Security threats to Android apps"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:38Z"}