REAPER: Real-time App Analysis for Augmenting the Android Permission System

REAPER: Real-time App Analysis for Augmenting the Android Permission System
复制标题

DOI:
10.1145/3292006.3300027
复制
发表时间:
2019-03
期刊:
Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
Michalis Diamantaris;Elias P. Papadopoulos;E. Markatos;S. Ioannidis;Jason Polakis
Michalis Diamantaris;Elias P. Papadopoulos;E. Markatos;S. Ioannidis;Jason Polakis
中科院分区:
其他
文献类型:
--
作者:
Michalis Diamantaris;Elias P. Papadopoulos;E. Markatos;S. Ioannidis;Jason Polakis

文献摘要

被引文献

相似文献

Android的应用生态系统严重依赖第三方库,因为它们促进了代码开发,并为开发人员提供了稳定的收入来源。然而,虽然Android已经转向更细粒度的运行时权限系统,但用户目前缺乏所需的资源来决定特定的权限请求实际上是针对应用本身还是由可能危险的第三方库请求的。在本文中,我们提出了一种新的动态分析系统Reaper,它可以真实的跟踪应用程序请求的权限,并区分应用程序的核心功能所请求的权限和与应用程序链接的第三方库所请求的权限。我们实现了一个复杂的UI自动化,并对我们的系统性能进行了广泛的评估,发现Reaper引入的开销可以忽略不计,使其既适合最终用户(通过将其集成到操作系统中),也适合作为官方应用程序审查过程的一部分进行部署。我们对超过5000个流行应用程序的研究表明,图书馆在很大程度上访问了个人身份信息,并强调了用户面临的隐私风险。我们发现,令人印象深刻的65%的权限请求不是来自核心应用程序,而是由链接的第三方库发布的,其中37.3%用于与广告,跟踪和分析相关的功能。总的来说,Reaper增强了Android运行时权限模型的功能,而无需对操作系统或应用进行修改,并提供了必要的上下文信息,使用户能够有选择地拒绝不属于应用核心功能的权限。
Android's app ecosystem relies heavily on third-party libraries as they facilitate code development and provide a steady stream of revenue for developers. However, while Android has moved towards a more fine-grained run time permission system, users currently lack the required resources for deciding whether a specific permission request is actually intended for the app itself or is requested by possibly dangerous third-party libraries. In this paper we present Reaper, a novel dynamic analysis system that traces the permissions requested by apps in real time and distinguishes those requested by the app's core functionality from those requested by third-party libraries linked with the app. We implement a sophisticated UI automator and conduct an extensive evaluation of our system's performance and find that Reaper introduces negligible overhead, rendering it suitable both for end users (by integrating it in the OS) and for deployment as part of an official app vetting process. Our study on over 5K popular apps demonstrates the large extent to which personally identifiable information is being accessed by libraries and highlights the privacy risks that users face. We find that an impressive 65% of the permissions requested do not originate from the core app but are issued by linked third-party libraries, 37.3% of which are used for functionality related to ads, tracking, and analytics. Overall, Reaper enhances the functionality of Android's run time permission model without requiring OS or app modifications, and provides the necessary contextual information that can enable users to selectively deny permissions that are not part of an app's core functionality.