website statistics

Google’s ‘Bouncer’ Can Be Fooled By Hackers To Hide Malicious Android Apps

When do you use Facebook?

View Results

Loading ... Loading ...
1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)
Loading ... Loading ...

Google has been trying to put in a tight security mechanism in the Android Market so that malicious apps are filtered away and are not allowed to stay in the apps market. In order to do so, Google makes use of a scanning program which is called ‘Bouncer.’ Now, security researchers have been able to identity the details of the antivirus scanner that Google uses, details that can be exploited by the hackers.


According to the research done by John Oberheide and Charlie Miller, Google’s antivirus scanner is called Miles Karlson and has one friend named Michelle K. Also, it is a fan of Lady Gaga.

By knowing even one of these many details, a malicious app can fool the scanner and make its way into the Android market. Miller and Oberheide will be presenting their research at the Summercon Conference which is scheduled for this week in New York. During the presentation, the two will present a new method to exploit the security of Google’s Android market scanners.

Google’s ‘Bouncer’ actually takes an app and then runs it on a virtual phone to check how does it work and whether or not it is involved in phishing user data or sending spam through his device. When all is rendered well, the app is considered safe, otherwise it is deemed malicious.

Miller and his co-researcher think that by making the app realize that it is being run on a simulation when ‘Bouncer’ is testing it, an app can appear safe during the test-drive and eventually, when it is approved, it can return to its malicious behaviour.

According to Oberheide, “The question for Google is, how do you make it so the malware doesn’t know it’s running in a simulated environment? You want to pretend you’re running a real system. But a lot of tricks can be played by malware to learn that it’s being monitored.”

Moreover, they say that there are ways to find out when a simulation is being run. For instance, a virtual program will be slower than an actual device and when Bouncer tries to contact Google’s servers during the simulation, the app can recognize the IP address of Google’s servers and then behave itself, knowing that it’s a test simulation.

Miller and Oberheide say they also contacted Google regarding this and that since then, Google has improved the security of the Bouncer so that it is difficult to differentiate between it and a real phone.

Source: Forbes

Buy Cheapest Related Product From Amazon.com


Sony Introduces PlayStation Move Racing Wheel At E3 2012

Lenovo Showcases Windows 8 Based ThinkPad Tablet
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On June 5, 2012(11 months, 19 days ago.)
  • http://www.collisionguard.com/ Delmer Le

    the IP address of Google’s servers and then behave itself, knowing that it’s a test simulation.


Recent Search

Recent Tutorials

This tutorial will show how to use S.M.A.R.T. (Self Monitoring Analysis and Reporting Technology) to continuously collect information on health of your equipment.
In this tutorial I'll show you how you can easily protect yourself from any kind of security breaks that may occur through Java.
Today Apple enabled "Two Step Verification" for iCloud And Apple ID. But the process is not that simple. But no worry, here we have made a step by step tutorial.
Cant remember your iPhone passcode? Here I will show you some workaround on what to do and how to recover and restore for every possible scenario.
This tutorial will show you how to perform the Winapp2.ini installation inside CCleaner and how to use it under Windows operating system.
With app called AD Sound Recorder, you can record any stream that passes through your sound card or speakers and in this tutorial I will show you how to do that.
If you want to have Boxee app inside your Apple TV, in this tutorial we will show you how to install XBMC and Boxee using Windows on your Apple TV.
This tutorial will show you how to transfer PS3 Saved Game Files from your PC to your PS3 game console.
Adding videos from external sources such as internet, more specifically from YouTube, is a great solution to enhance a presentation; in this tutorial I will show you the procedure.
If you are one of new comers to Windows Phone 8, like me, in this tutorial I will walk you through the process to update your Windows Phone 8 device.
Close You Have To Login
User:
Pass:
Login With »Login With TwitterLogin With Facebook