An effective access control scheme for preventing permission leak in Android

An effective access control scheme for preventing permission leak in Android
复制标题

Android中防止权限泄露的有效访问控制方案

DOI:
10.1109/iccnc.2015.7069315
复制
发表时间:
2015
期刊:
2015 International Conference on Computing, Networking and Communications (ICNC)
影响因子:
--
通讯作者:
Hongli Zhang
Hongli Zhang
中科院分区:
--
文献类型:
--
作者:
Longfei Wu;Xiaojiang Du;Hongli Zhang

文献摘要

被引文献

相似文献

在Android系统中,每个应用程序都运行在自己的沙箱中,通过权限机制对系统API和应用程序进行访问控制。然而,当没有特定权限的应用程序通过其他特权应用程序非法访问受保护的资源时,可能会发生权限泄漏。我们提出SPAC,一种基于组件级系统权限的访问控制方案,可以帮助开发人员更好地保护其应用程序的公共组件。在 SPAC 方案中,模糊的自定义权限被显式的系统权限取代。我们扩展了当前的权限检查机制,以便在组件级别支持多个权限。 SPAC 已在 Nexus 4 智能手机上实施,我们的评估证明了其在缓解权限泄漏漏洞方面的有效性。
In the Android system, each application runs in its own sandbox, and the permission mechanism is used to enforce access control to the system APIs and applications. However, permission leak could happen when an application without certain permission illegally gain access to protected resources through other privileged applications. We propose SPAC, a component-level system permission based access control scheme that can help developers better secure the public components of their applications. In the SPAC scheme, obscure custom permissions are replaced by explicit system permissions. We extend current permission checking mechanism so that multiple permissions are supported on component level. SPAC has been implemented on a Nexus 4 smartphone, and our evaluation demonstrates its effectiveness in mitigating permission leak vulnerabilities.