article · Science World Journal
Google Play Store security countermeasures exhibit vulnerabilities, particularly because users frequently grant all requested permissions without understanding the associated risks. To expose and exploit these weaknesses in the Android operating system, an experimental malware application was developed using object-oriented analysis and design methodology. The architecture incorporated context diagrams for data flow, sequence diagrams for object interactions, and a randomised algorithm for detailed implementation. While monitoring user tasks, the application ran in the background and systematically altered the stored contacts list by replacing entries with randomised alphanumeric strings. By simulating real-world cyber threats that evade conventional security measures, the study demonstrated how malicious applications can exploit basic permission structures to manipulate device data.
Smartphone users regularly grant permissions to applications without understanding the underlying security implications. Demonstrating how background software can silently alter vital personal data, such as contact directories, highlights critical gaps in current mobile app store vetting. Understanding these attack pathways allows security teams and operating system architects to design better safeguards against covert mobile threats.
The abstract demonstrates an early-stage experimental attack simulation rather than a commercial product. The insights could inform mobile operating system developers and cybersecurity firms seeking to refine permission models and threat detection software. However, the abstract focuses purely on proving vulnerabilities experimentally, indicating that any direct commercial application or security product remains at a very early stage of research.
AI-generated from the published abstract. Always read the original work before citing.
Android operating system has become one of the platforms developers used to introduce their malicious activities into the smartphone world through Android Applications (App). Although the Google Play Store implements security countermeasures against Android malware, these measures have vulnerabilities. A major weakness is that users often accept all requested permissions as mandatory when installing an application, without understanding the risks. This gives developers the basis to achieve their illicit actions. The aim of the study is to develop a malware application for identification and to exploit vulnerabilities within the android operating system. The work adopted the object-oriented analysis and design methodology (OOAD). Context diagram was used to represent data flow in the malware application and Sequence diagram was used to show the interactions between objects in the application and the sequential order that those interactions occurred. Further, a randomized algorithm was used for the detailed design. The work developed a malware application that kept track of user tasks but at the background modified contacts list causing inconveniences to the user. The malware application replaced the contact list with random strings from set of alphanumeric characters. The malware application simulated a real-world cyber threat, contacts modification, to uncover vulnerabilities that evade detection through conventional security approaches. By exploring this attack vector, the study provided empirical evidence of vulnerabilities that was exploited by the malicious application developed. This study contributed to the broader field of cyber security research by providing experimental evidence and insights into the specific vulnerabilities and attack vectors targeting Android operating system.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.4314/swj.v20i1.22
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.