Shweta Bhandari

dblp:168/1132 · DBLP profile ↗
← Back
9ranked-venue papers
6as first author
2since 2021 · last 2025
0000-0002-2701-9866ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2025 MOSDroid: Obfuscation-resilient android malware detection using multisets of encoded opcode sequences
Yogesh Kumar Sharma, Deepak Singh Tomar, Rajesh Kumar Pateriya, Shweta Bhandari
Comput. Secur.4
2021 Unmasking Privacy Leakage through Android Apps Obscured with Hidden Permissions
abstract
Data theft is a significant security threat for mobile app users. The growing importance of digitization motivates the diversity of available applications. In this paper, we propose a novel and lightweight method for classifying Android apps into low, medium, and high-risk categories. Our approach relies largely on the other permissions (also termed as hidden permissions) of the Android applications. We have proposed a linear regression-based technique to classify the apps into different risk categories. We will show how other permissions can be used as a strong indicator for defining risk categories. We have used K-means clustering to validate and explain the decision of our method. In an evaluation with 500 applications and 101 other permissions, our proposed approach decides the risk factor of an app, and the explanation is provided for each detection reveal relevant properties of the detected risk.
Pranav Kotak, Shweta Bhandari, Akka Zemmari, Jaykrishna Joshi
PST2
2020 SneakLeak+: Large-scale klepto apps analysis
Shweta Bhandari, Frédéric Herbreteau, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur, Partha S. Roop
Future Gener. Comput. Syst.1
2018 SWORD: Semantic aWare andrOid malwaRe Detector
Shweta Bhandari, Rekha Panihar, Smita Naval, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur
J. Inf. Secur. Appl.1
2017 Detecting Inter-App Information Leakage Paths
abstract
Sensitive (private) information can escape from one app to another using one of the multiple communication methods provided by Android for inter-app communication. This leakage can be malicious. In such a scenario, individual benign app, in collusion with other conspiring apps, if present, can leak the private information. In this work in progress, we present, a new model-checking based approach for inter-app collusion detection. The proposed technique takes into account simultaneous analysis of multiple apps. We are able to identify any set of conspiring apps involved in the collusion. To evaluate the efficacy of our tool, we developed Android apps that exhibit collusion through inter-app communication. Eight demonstrative sets of apps have been contributed to widely used test dataset named DroidBench. Our experiments show that proposed technique can accurately detect the presence/absence of collusion among apps. To the best of our knowledge, our proposal has improved detection capability than other techniques.
Shweta Bhandari, Frédéric Herbreteau, Vijay Laxmi, Akka Zemmari, Partha S. Roop, Manoj Singh Gaur
AsiaCCS1
2017 Android inter-app communication threats and detection techniques
Shweta Bhandari, Wafa Ben Jaballah, Vineeta Jain, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur, Mohamed Mosbah 0001, Mauro Conti
Comput. Secur.1
2016 Intersection Automata Based Model for Android Application Collusion
abstract
Android applications need to access and share user's sensitive data. To maintain user's privacy and related data security, it is essential to protect this data. Android security framework enforces permission protected model but it has been shown that applications can bypass this security model. Attacks based on such unauthorized privileges are known as Inter-Component Communication (ICC) Collusion Attacks. In this paper, we propose, a novel automaton framework that allows effective detection of intent based collusion. Our detection framework operates at the component-level. To evaluate our proposal, we developed 14 applications and took 4 applications from Google Play Store. We took all possible combinations from the set of 21 applications. We tested our approach on 210 pairs of applications derived from the set of 21 applications. Time and space complexity of our proposed approach isO(n) where n is the number of components in all the applications under analysis. The experimental results demonstrate that our technique is scalable to application sizing and more efficient as compared to other state of the art approaches.
Shweta Bhandari, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur
AINA1
2016 FlowMine: Android app analysis via data flow
abstract
The demeanor towards sensitive data is an important factor to differentiate malicious apps from benign apps in Android platform. In this work, we consider the data flow path from a data source to a data sink, where `source' is a non-constant data that marks the beginning of the path, and `sink' is the resource where the data reaches. To accurately identify the behavioral differences, we analyzed the data flow paths in 2800 benign apps against 15000 malicious apps. We assigned weights to each path which is the absolute difference between its use in benign and malicious samples. If a path is more used by malicious apps, then weight becomes negative otherwise positive. We assigned rankings according to the popularity of the path. If the benignity rank of a path is higher than its malignity rank, then it can be inferred that the path is more used by benign application. We cover all possible paths in an application based on context-sensitivity, flow-sensitivity, and object-sensitivity of data. We name our proposed solution FlowMine. FlowMine takes these rankings and weights as its contrivance and evaluates the behavior of any test application towards maliciousness or benignity. For evaluation purpose, we took 5000 benign and 10000 malware samples. To the best of our knowledge, FlowMine is the first approach that finds the degree of similarity of an unknown sample app with known benign and malware samples for the classification of app. Our prototype excelled and correctly classified 96% of all benign apps and 98% of all novel malware leaking sensitive data.
Lovely Sinha, Shweta Bhandari, Parvez Faruki, Manoj Singh Gaur, Vijay Laxmi, Mauro Conti
CCNC2
2015 DRACO: DRoid analyst combo an android malware analysis framework
abstract
Android being the most popular open source mobile operating system, attracts a plethora of app developers. Millions of applications are developed for Android platform with a great extent of behavioral diversities and are available on Play Store as well as on many third party app stores. Due to its open nature, in the past Android Platform has been targeted by many malware writers. The conventional way of signature-based detection methods for detecting malware on a device are no longer promising due to an exponential increase in the number of variants of the same application with different signatures. Moreover, they lack in dynamic analysis too. In this paper, we propose DRACO, which employs a two-phase detection technique that blends the synergy of both static and dynamic analysis. It has two modules, client module that is in the form an Android app and gets installed on mobile devices and a server module that runs on a server. DRACO also explains user about the features contributing to the maliciousness of analyzed app and generates scoring for that maliciousness. It does not require any root or super-user privileges. In an evaluation of 18,000 benign applications and 10,000 malware samples, DRACO performs better than several related existing approaches and detects 98.4% of the malware with few false alerts. On ten popular smartphones, the method requires an average of 6 seconds for on device analysis and 90 seconds on server analysis.
Shweta Bhandari, Vijay Laxmi, Manoj Singh Gaur, Akka Zemmari, Maxim Anikeev
SIN1