计算机科学
计算机安全
Android(操作系统)
隐蔽的
互联网隐私
移动设备
工程类
Android应用程序
Rootkit
钥匙(锁)
作者
Ye Wang,Bo Luo,Fengjun Li
标识
DOI:10.14722/ndss.2026.240348
摘要
Recent advances in static analysis, fuzzing, and learning-based detection have substantially improved the defense against trigger-based malware; however, these approaches mostly assume that trigger conditions are semantically explicit or distinguishable from normal application logic.In this paper, we present SensorBomb, a novel logic-bomb framework that exploits this assumption through auto-contextualized triggers and onboard sensor-actuator covert channels.Instead of relying on obscure or rare trigger conditions, SensorBomb constructs triggers tightly aligned with the host app's legitimate sensor usage, actuator behaviors, and functional context so that they appear indistinguishable from benign behavior.To do so, SensorBomb automatically analyzes the host app to select context-compatible sensors, actuators, and sensitive operations, constructs covert trigger channels, and dynamically adapts trigger patterns to evade static analysis, fuzzing, sensor state anomaly detection, and user suspicion.We implement three representative prototypes of such triggers and evaluate them across diverse devices and environments.Our results show that SensorBomb consistently evades state-of-theart detection techniques and achieves high trigger reliability with zero false positives.Large-scale injection experiments on real-world APKs further demonstrate that SensorBomb can be deployed without affecting normal app functionality.This work reveals a critical and previously underexplored attack surface in mobile malware defenses and calls for more advanced detection mechanisms.
科研通智能强力驱动
Strongly Powered by AbleSci AI