Inviting an author to review:
Find an author and click ‘Invite to review selected article’ near their name.
Search for authorsSearch for similar articles
1
views
0
recommends
+1 Recommend
0 collections
    0
    shares
      • Record: found
      • Abstract: found
      • Article: found
      Is Open Access

      Simple Spyware: Androids Invisible Foreground Services and How to (Ab)use Them

      Preprint

      Read this article at

      Bookmark
          There is no author summary for this article yet. Authors can add summaries to their articles on ScienceOpen to make them more accessible to a non-specialist audience.

          Abstract

          With the releases of Android Oreo and Pie, Android introduced some background execution limitations for apps. Google restricted the execution of background services to save energy and to prevent apps from running endlessly in the background. Moreover, access to the device's sensors was changed and a new concept named foreground service has been introduced. Apps were no longer allowed to run background services in an idle state, preventing apps from using the device's resources like the camera. These limitations, however, would not affect so-called foreground services because they show a permanently visible notification to the user and could therefore be stopped by the user at any time. Our research found out that flaws in the API exists, which allows starting invisible foreground services, making the introduced limitations ineffective. We will show that the found flaws allow attackers to use foreground services as a tool for spying on users.

          Related collections

          Author and article information

          Journal
          28 November 2020
          Article
          2011.14117
          cca70043-e9f4-4a72-b7b6-bdfc5e20c51c

          http://creativecommons.org/licenses/by-nc-nd/4.0/

          History
          Custom metadata
          9 pages, 2 figures, 3 listings, BlackHat Europe 2019 see https://www.blackhat.com/eu-19/briefings/schedule/index.html#simple-spyware-androids-invisible-foreground-services-and-how-to-abuse-them-17738, WhitePaper
          cs.CR

          Security & Cryptology
          Security & Cryptology

          Comments

          Comment on this article