On lightweight mobile phone application certification

On lightweight mobile phone application certification
复制标题

DOI:
10.1145/1653662.1653691
复制
发表时间:
2009-11
期刊:
影响因子:
6.2
通讯作者:
W. Enck;Machigar Ongtang;P. Mcdaniel
W. Enck;Machigar Ongtang;P. Mcdaniel
中科院分区:
化学2区
文献类型:
--
作者:
W. Enck;Machigar Ongtang;P. Mcdaniel

文献摘要

被引文献

相似文献

Users have begun downloading an increasingly large number of mobile phone applications in response to advancements in handsets and wireless networks. The increased number of applications results in a greater chance of installing Trojans and similar malware. In this paper, we propose the Kirin security service for Android, which performs lightweight certification of applications to mitigate malware at install time. Kirin certification uses security rules, which are templates designed to conservatively match undesirable properties in security configuration bundled with applications. We use a variant of security requirements engineering techniques to perform an in-depth security analysis of Android to produce a set of rules that match malware characteristics. In a sample of 311 of the most popular applications downloaded from the official Android Market, Kirin and our rules found 5 applications that implement dangerous functionality and therefore should be installed with extreme caution. Upon close inspection, another five applications asserted dangerous rights, but were within the scope of reasonable functional needs. These results indicate that security configuration bundled with Android applications provides practical means of detecting malware.