Malevolent app pairs: an Android permission overpassing scheme

Malevolent app pairs: an Android permission overpassing scheme
复制标题

恶意应用程序对:Android权限越权方案

DOI:
10.1145/2903150.2911706
复制
发表时间:
2016
期刊:
Proceedings of the ACM International Conference on Computing Frontiers
影响因子:
--
通讯作者:
Vasilios Katos
Vasilios Katos
中科院分区:
--
文献类型:
--
作者:
Antonios Dimitriadis;P. Efraimidis;Vasilios Katos

文献摘要

被引文献

相似文献

便携式智能设备可能存储大量个人数据信息,使其成为数据泄露攻击的诱人目标。基于权限的方案是降低隐私和安全风险的核心安全控制。在本文中,我们证明了当前的许可方案不能有效地减轻隐蔽通道带来的风险。我们展示了一对具有不同权限设置的应用程序可能会串通,以便有效地创建一种状态,在这种状态下获得他们的权限联合,从而为泄露敏感数据提供机会,同时保持泄漏可能不被注意。然后,我们提出了针对此类攻击的解决方案。
Portable smart devices potentially store a wealth of information of personal data, making them attractive targets for data exfiltration attacks. Permission based schemes are core security controls for reducing privacy and security risks. In this paper we demonstrate that current permission schemes cannot effectively mitigate risks posed by covert channels. We show that a pair of apps with different permission settings may collude in order to effectively create a state where a union of their permissions is obtained, giving opportunities for leaking sensitive data, whilst keeping the leak potentially unnoticed. We then propose a solution for such attacks.