Tap-Wave-Rub: Lightweight Malware Prevention for Smartphones Using Intuitive Human Gestures
Haoyu Li, Di Ma, Nitesh Saxena, Babins Shrestha, and Yan Zhu

TL;DR
Tap-Wave-Rub (TWR) is a lightweight, gesture-based malware prevention method for smartphones that uses simple, intuitive gestures detected by sensors to determine application safety with minimal user burden.
Contribution
The paper introduces TWR, a novel gesture-based permission enforcement system for smartphones, including sensor mechanisms and an enhanced Android permission model.
Findings
High accuracy in gesture detection with low false positives/negatives
Effective malware prevention with minimal user burden
Prototype implementation demonstrating practicality
Abstract
In this paper, we introduce a lightweight permission enforcement approach - Tap-Wave-Rub (TWR) - for smartphone malware prevention. TWR is based on simple human gestures that are very quick and intuitive but less likely to be exhibited in users' daily activities. Presence or absence of such gestures, prior to accessing an application, can effectively inform the OS whether the access request is benign or malicious. Specifically, we present the design of two mechanisms: (1) accelerometer based phone tapping detection; and (2) proximity sensor based finger tapping, rubbing or hand waving detection. The first mechanism is geared for NFC applications, which usually require the user to tap her phone with another device. The second mechanism involves very simple gestures, i.e., tapping or rubbing a finger near the top of phone's screen or waving a hand close to the phone, and broadly appeals…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · User Authentication and Security Systems · Internet Traffic Analysis and Secure E-voting
