Improving the security of Android inter-component communication

Improving the security of Android inter-component communication
复制标题

提高Android组件间通信的安全性

DOI:
--
复制
发表时间:
2013
期刊:
2013 IFIP/IEEE International Symposium on Integrated Network Management (IM 2013)
影响因子:
--
通讯作者:
P. Reiher
P. Reiher
中科院分区:
--
文献类型:
--
作者:
Adam Cozzette;K. Lingel;Steve Matsumoto;Oliver Ortlieb;Jandria Alexander;J. Betser;Luke Florer;G. Kuenning;J. Nilles;P. Reiher

文献摘要

被引文献

相似文献

在 Android 操作系统中,每个应用程序都由一组组件组成,这些组件通过称为 Intents 的消息相互通信。目前 Intent 处理的实现方式是,开发人员可能会无意中编写不安全的代码,从而允许恶意应用程序拦截或注入 Intent,以窃取敏感信息或引发不良行为。我们通过修改 Android 的 Intent 处理行为来防止这些漏洞,以确保安全,除非开发人员似乎明确指定了其他方式。此外,我们通过分析 Android 官方应用市场中 497 个最受欢迎的免费应用程序,确认了 Intent 漏洞的普遍性,并通过手动验证修改是否修复了我们发现的大量安全漏洞,证明了我们修改的有效性。
In the Android operating system, each application consists of a set of components that communicate with each other via messages called Intents. The current implementation of Intent handling is such that developers can inadvertently write insecure code that allows malicious applications to intercept or inject Intents to steal sensitive information or induce undesired behavior. We prevented these exploits by modifying Android's Intent handling behavior to err on the side of safety except where the developer seems to explicitly specify otherwise. Additionally, we confirmed the pervasiveness of Intent vulnerabilities by analyzing the 497 most popular free applications in Android's official application market, and proved the effectiveness of our modifications by manually verifying that they closed a substantial number of the security holes we identified.