Malevolent app pairs: an Android permission overpassing scheme
Malevolent app pairs: an Android permission overpassing scheme
复制标题
恶意应用程序对:Android权限越权方案
DOI:
10.1145/2903150.2911706
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Vasilios Katos
中科院分区:
文献类型:
--
作者:
Antonios Dimitriadis;P. Efraimidis;Vasilios Katos
Portable smart devices potentially store a wealth of information of personal data, making them attractive targets for data exfiltration attacks. Permission based schemes are core security controls for reducing privacy and security risks. In this paper we demonstrate that current permission schemes cannot effectively mitigate risks posed by covert channels. We show that a pair of apps with different permission settings may collude in order to effectively create a state where a union of their permissions is obtained, giving opportunities for leaking sensitive data, whilst keeping the leak potentially unnoticed. We then propose a solution for such attacks.