Please use this identifier to cite or link to this item: https://www.um.edu.mt/library/oar/handle/123456789/91722
Full metadata record
DC FieldValueLanguage
dc.date.accessioned2022-03-17T16:49:26Z-
dc.date.available2022-03-17T16:49:26Z-
dc.date.issued2019-
dc.identifier.citationBellizzi, J., Vella, M., & Colombo, C. (2019). Living off Android’s accessible land. Computer Science Annual Workshop (No. CS-2019-03). University of Maltaen_GB
dc.identifier.urihttps://www.um.edu.mt/library/oar/handle/123456789/91722-
dc.description.abstractAndroid’s accessibility services provide individuals having disabilities, including visual, hearing, physical, and/or speech impairments, with tools to enhance their ability to access and interact with apps. Even though this feature was originally intended exclusively for users with disabilities, this is not always the case. Besides being used to automate processes in apps such as password managers (e.g., Lastpass), malware is also abusing this powerful feature to perform nefarious operations. In this talk, we demonstrate how accessibility can be used to bypass assumed security features. By using a ‘living off the land’ (LOtL) approach, malware is able to use accessibility to piggyback on existing applications to grant it full access to their privileged functionality whilst achieving long-term stealth. This is demonstrated through a number of use cases including an SMS hijack implementation and Whatsapp message theft and exfiltration, all of which are executed using only the accessibility permission. These use cases will form a basis for the development of a pentest tool which will be used to perform a threat analysis on the permissions that can be bypassed through the use of accessibility across different Android versions and configurations.en_GB
dc.language.isoenen_GB
dc.publisherUniversity of Malta. Department of Computer Scienceen_GB
dc.rightsinfo:eu-repo/semantics/restrictedAccessen_GB
dc.subjectAndroidsen_GB
dc.subjectAssistive computer technologyen_GB
dc.subjectMalware (Computer software)en_GB
dc.titleLiving off Android’s accessible landen_GB
dc.title.alternativeComputer science annual workshopen_GB
dc.typereporten_GB
dc.rights.holderThe copyright of this work belongs to the author(s)/publisher. The rights of this work are as defined by the appropriate Copyright Legislation or as modified by any successive legislation. Users may access this work and can make use of the information contained in accordance with the Copyright Legislation provided that the author must be properly acknowledged. Further distribution or reproduction in any format is prohibited without the prior permission of the copyright holderen_GB
dc.description.reviewedN/Aen_GB
dc.contributor.creatorLeguesse, Yonas-
dc.contributor.creatorVella, Mark Joseph-
dc.contributor.creatorColombo, Christian-
Appears in Collections:Scholarly Works - FacICTCS

Files in This Item:
File Description SizeFormat 
Living_off_androids_accessible_land.pdf
  Restricted Access
167.97 kBAdobe PDFView/Open Request a copy


Items in OAR@UM are protected by copyright, with all rights reserved, unless otherwise indicated.