Data leakage between C/S communication: A case study on Android music app

Huanhuan Li, Qian Luo, Shubin Zhang, Haibin Zhang, Jiajia Liu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

As the rapid development of mobile communication technology, smartphones have become indispensable elements in our daily life. Particularly, the increasingly rich smartphone applications (apps) bring great convenience to people while the defects generated in app designing and coding may pose unexpected threats to users. In this paper, we focus on the issue of data leakage between the app client and server. By analyzing the vulnerabilities of client-to-server communication and eavesdropping on the session data, we implement spoofing attack on a popular music app client. Two experiments are introduced in details: downloading songs freely by means of bypassing the payment mechanism and deceiving user into installing malware. In addition, the countermeasures are also provided.

Original languageEnglish
Title of host publication2017 9th International Conference on Wireless Communications and Signal Processing, WCSP 2017 - Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1-6
Number of pages6
ISBN (Electronic)9781538620625
DOIs
StatePublished - 7 Dec 2017
Externally publishedYes
Event9th International Conference on Wireless Communications and Signal Processing, WCSP 2017 - Nanjing, China
Duration: 11 Oct 201713 Oct 2017

Publication series

Name2017 9th International Conference on Wireless Communications and Signal Processing, WCSP 2017 - Proceedings
Volume2017-January

Conference

Conference9th International Conference on Wireless Communications and Signal Processing, WCSP 2017
Country/TerritoryChina
CityNanjing
Period11/10/1713/10/17

Fingerprint

Dive into the research topics of 'Data leakage between C/S communication: A case study on Android music app'. Together they form a unique fingerprint.

Cite this