Systematic Detection of Capability Leaks in Stock Android Smartphones

Systematic Detection of Capability Leaks in Stock Android Smartphones
复制标题

DOI:
--
复制
发表时间:
2012
期刊:
--
影响因子:
--
通讯作者:
Michael C. Grace;Yajin Zhou;Zhi Wang;Xuxian Jiang
Michael C. Grace;Yajin Zhou;Zhi Wang;Xuxian Jiang
中科院分区:
其他
文献类型:
--
作者:
Michael C. Grace;Yajin Zhou;Zhi Wang;Xuxian Jiang

文献摘要

被引文献

相似文献

近年来,智能手机的使用量急剧增加。为了管理此类手机上的信息和功能,安卓提供了一种基于权限的安全模型,该模型要求每个应用程序在安装运行之前明确请求权限。在本文中,我们分析了八款流行的安卓智能手机,发现手机的原生系统镜像没有正确实施权限模型。一些特权权限不安全地暴露给了其他应用程序,这些应用程序在实际使用时无需请求这些权限。为了识别这些泄露的权限或能力,我们开发了一种名为啄木鸟(Woodpecker)的工具。我们对八款手机系统镜像的研究结果表明,在迄今为止所检查的13种特权权限中,有11种被泄露,个别手机泄露的权限多达8种。通过利用这些权限,一个不受信任的应用程序能够删除用户数据、发送短信或在受影响的手机上记录用户通话——所有这些操作都无需请求任何权限。
Recent years have witnessed a meteoric increase in the adoption of smartphones. To manage information and features on such phones, Android provides a permission-based security model that requires each application to explicitly request permissions before it can be installed to run. In this paper, we analyze eight popular Android smartphones and discover that the stock phone images do not properly enforce the permission model. Several privileged permissions are unsafely exposed to other applications which do not need to request them for the actual use. To identify these leaked permissions or capabilities, we have developed a tool called Woodpecker. Our results with eight phone images show that among 13 privileged permissions examined so far, 11 were leaked, with individual phones leaking up to eight permissions. By exploiting them, an untrusted application can manage to wipe out the user data, send out SMS messages, or record user conversation on the affected phones – all without asking for any permission.