2019 IEEE European Symposium on Security and Privacy (EuroS&P) 2019
DOI: 10.1109/eurosp.2019.00011
|View full text |Cite
|
Sign up to set email alerts
|

False Sense of Security: A Study on the Effectivity of Jailbreak Detection in Banking Apps

Abstract: People increasingly rely on mobile devices for banking transactions or two-factor authentication (2FA) and thus trust in the security provided by the underlying operating system. Simultaneously, jailbreaks gain tremendous popularity among regular users for customizing their devices. In this paper, we show that both do not go well together: Jailbreaks remove vital security mechanisms, which are necessary to ensure a trusted environment that allows to protect sensitive data, such as login credentials and transac… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
10
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
5
2
1

Relationship

0
8

Authors

Journals

citations
Cited by 12 publications
(10 citation statements)
references
References 33 publications
0
10
0
Order By: Relevance
“…To the best of our knowledge, no work targeting the autonomous evaluation of risk indicators exists yet. In this section, we will, therefore, discuss existing work for the individual parts of FedCRI, covering the detection of risks on smartphones [29], [53], [23], [32], [44], [26], [56], coordination of different clients for threat intelligence [28], [9], [17], [13] and leveraging ML for detecting risks and anomalies [49], [42].…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…To the best of our knowledge, no work targeting the autonomous evaluation of risk indicators exists yet. In this section, we will, therefore, discuss existing work for the individual parts of FedCRI, covering the detection of risks on smartphones [29], [53], [23], [32], [44], [26], [56], coordination of different clients for threat intelligence [28], [9], [17], [13] and leveraging ML for detecting risks and anomalies [49], [42].…”
Section: Related Workmentioning
confidence: 99%
“…Jailbreak Detection: Several strategies to detect rooted or jailbroken devices have been developed [29], [53]. They focus on hard-coded heuristic checks, e.g., to determine whether certain parts of the file system [29] are writable (such as "/system" [53]), or, whether certain program files are indicative of privilege escalation (e.g., the su application on android [53]), and typical applications on jailbroken devices (like alternative app stores on iOS devices [29]), are present on the device. In contrast to these, FedCRI performs holistic risk evaluation based on several different risk factors simultaneously for more accurate detection results.…”
Section: Related Workmentioning
confidence: 99%
“…(1) Security mechanisms should be utilized to secure the servers and API to prevent any form of unauthorized access (2) Since the data in mobiles are highly confidential, encryption procedures should be timely applied [34,35]. (3) Protecting the source code must be prioritized at all levels of analysis and compilers to secure and enhance the confidentiality of the intellectual property (4) A two-factor authentication system should be applied to protect users' sensitive data [36,37]…”
Section: Security Countermeasuresmentioning
confidence: 99%
“…security to obstruct unauthorized alternation of the operating system. A jailbreak is an advanced attack that dispels the prevention of the iOS software to entrance a device and the file system [82]. On the other hand, for the Android operating system, it is known as rooting the device [82].…”
Section: Operating System Securitymentioning
confidence: 99%
“…A jailbreak is an advanced attack that dispels the prevention of the iOS software to entrance a device and the file system [82]. On the other hand, for the Android operating system, it is known as rooting the device [82]. In the case of banking and Fintech apps, it's significant to make sure Android root prohibition and iOS jailbreak preclusion.…”
Section: Operating System Securitymentioning
confidence: 99%