ZTA: a novel zero trust framework for detection and prevention of malicious android applications
摘要
The proliferation of preloaded and third-party applications has raised significant concerns regarding user security and privacy. This study introduces the Zero Trust Architecture (ZTA) to address the issues caused by poorly designed vulnerable mobile applications. ZTA employs a comprehensive strategy to safeguard user privacy, incorporating thorough app permission analysis alongside dynamic behavior assessment. The proposed framework closely monitors real-time app behavior and leverages the MITRE ATT&CK framework to identify security threats, vulnerabilities, and essential Tactics, Techniques, and Procedures (TTPs). This research contributes in four key ways: it highlights the urgent need for a proactive approach to mobile app security in light of evolving cyber threats, demonstrates the benefits of utilizing the MITRE ATT&CK framework to map potential attack paths and identify security weaknesses in mobile apps, proposes the adoption of a Zero Trust framework for continuous authentication and verification to mitigate vulnerabilities in the mobile app ecosystem, and explores the impact of various app categories on user privacy and security, providing valuable insights into real-world threats. Research findings revealed that approximately 40–60% of applications in the analyzed categories engaged in malicious behavior, stealthily collecting personal data, and employing deceptive practices, underscoring the urgency for improved security measures and user awareness. Overall, this research extends the area of Android security by presenting a Zero Trust-based unique method for identifying and combating malware attacks on Android smartphones while also providing valuable insights to assess the performance of the proposed solution, which researchers and practitioners can leverage to enhance the security of mobile devices.