Improving the security of Android inter-component communication
Improving the security of Android inter-component communication
复制标题
提高Android组件间通信的安全性
DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
P. Reiher
中科院分区:
文献类型:
--
作者:
Adam Cozzette;K. Lingel;Steve Matsumoto;Oliver Ortlieb;Jandria Alexander;J. Betser;Luke Florer;G. Kuenning;J. Nilles;P. Reiher
In the Android operating system, each application consists of a set of components that communicate with each other via messages called Intents. The current implementation of Intent handling is such that developers can inadvertently write insecure code that allows malicious applications to intercept or inject Intents to steal sensitive information or induce undesired behavior. We prevented these exploits by modifying Android's Intent handling behavior to err on the side of safety except where the developer seems to explicitly specify otherwise. Additionally, we confirmed the pervasiveness of Intent vulnerabilities by analyzing the 497 most popular free applications in Android's official application market, and proved the effectiveness of our modifications by manually verifying that they closed a substantial number of the security holes we identified.