DroidForce: Enforcing Complex, Data-centric, System-wide Policies in Android

DroidForce: Enforcing Complex, Data-centric, System-wide Policies in Android
复制标题

DOI:
10.1109/ares.2014.13
复制
发表时间:
2014-09
期刊:
2014 Ninth International Conference on Availability, Reliability and Security
影响因子:
--
通讯作者:
Siegfried Rasthofer;Steven Arzt;Enrico Lovat;E. Bodden
Siegfried Rasthofer;Steven Arzt;Enrico Lovat;E. Bodden
中科院分区:
其他
文献类型:
--
作者:
Siegfried Rasthofer;Steven Arzt;Enrico Lovat;E. Bodden

文献摘要

被引文献

相似文献

如今,智能手机用于存储和处理多种对隐私敏感的数据,例如联系人,照片和电子邮件。传感器可访问手机的物理位置,并可以录制音频和视频。尽管这对于许多应用程序都方便,但它也使智能手机成为提供恶意应用程序的攻击者的值得目标。当前的运行时执行方法试图减轻机密数据的未经授权泄漏。但是,它们通常只能执行一套非常有限的策略,例如仅在单个组件中防止数据泄漏或仅监视对特定敏感系统资源的访问。在这项工作中,我们提出了Droid Force,这是一种在Android应用上执行复杂,以数据为中心的全系统策略的方法。 Droid Force允许用户在手机上如何以及何时处理哪些数据,无论恶意行为是否在不同的勾结组件甚至应用程序上分布,都可以在手机上处理哪些数据。可以在运行时动态交换策略,并且不需要对操作系统进行修改,也不需要对手机的根访问。 Droid Force纯粹在应用水平上工作。它提供了一个集中的政策决策点作为专用的Android应用程序,并且它可以在每个目标应用程序中使用分散的政策执行点。分析和仪器的应用程序总共需要不到一分钟的时间,而有担保的应用程序在实践中没有明显的放缓。
Smartphones are nowadays used to store and process many kinds of privacy-sensitive data such as contacts, photos, and e-mails. Sensors provide access to the phone's physical location, and can record audio and video. While this is convenient for many applications, it also makes smartphones a worthwhile target for attackers providing malicious applications. Current approaches to runtime enforcement try to mitigate unauthorized leaks of confidential data. However, they are often capable of enforcing only a very limited set of policies, like preventing data leaks only within single components or monitoring access only to specific sensitive system resources. In this work, we present Droid Force, an approach for enforcing complex, data-centric, system-wide policies on Android applications. Droid Force allows users to specify fine-grained constraints on how and when which data may be processed on their phones, regardless of whether the malicious behavior is distributed over different colluding components or even applications. Policies can be dynamically exchanged at runtime and no modifications to the operating system nor root access to the phone are required. Droid Force works purely on the application level. It provides a centralized policy decision point as a dedicated Android application and it instruments a decentralized policy enforcement point into every target application. Analyzing and instrumenting an application takes in total less than a minute and secured applications exhibit no noticeable slowdown in practice.