Apps on web-enabled mobile devices can be used to spy on their users, so researchers from the Saarland University in Germany developed the new software to track malicious activity by an app.
Last year at the end of July the Russian software company "Doctor Web" detected several malicious apps in the app store "Google Play", researchers said.
Also Read
Although Doctor Web, according to its own statement, informed Google immediately, the malicious apps were still available for download for several days, researchers said.
Doctor Web estimates that in this way up to 25,000 smartphones were used fraudulently.
The new software can discover such malicious apps already in the app store. The software detects pieces of code where the app accesses sensitive data and where data is sent from the mobile device.
If the software detects a connection between such a "source" and such a "sink", it reports that as suspect behaviour.
Researchers demonstrated a malicious source-sink combination with an example.
"Your address book is read; hundreds of instructions later and without your permission an SMS is sent or a website is visited," said Erik Derr, who does research at the Center for IT-Security, Privacy and Accountability (CISPA) of Saarland University.
To identify a functional relation between source and sink, the computer scientists use new methods of information flow analysis.
As input they provide suspicious combinations of accesses on the application programming interface. As the software needs a lot of computational power and storage, it runs on a separate server.
"So far we have tested up to 3,000 apps with it. The software analyses them fast enough that the approach can also be used in practice," Derr said.
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
)