Reducing attack surfaces for intra-application communication in android

Reducing attack surfaces for intra-application communication in android
复制标题

减少 Android 中应用程序内通信的攻击面

DOI:
10.1145/2381934.2381948
复制
发表时间:
2012
期刊:
Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security
影响因子:
--
通讯作者:
D. Wagner
D. Wagner
中科院分区:
--
文献类型:
--
作者:
David Kantola;Erika Chin;Warren He;D. Wagner

文献摘要

被引文献

相似文献

Android消息传递系统的复杂性导致第三方应用程序中存在大量漏洞。其中许多漏洞是开发人员混淆应用程序间和应用程序内通信机制的结果。因此,我们建议对Android平台进行修改,以检测和保护本应是应用内消息的应用间消息。我们的方法会自动减少遗留应用程序中的攻击面。我们描述了我们对这些更改的实现,并根据攻击面的减少以及我们的更改破坏了与大量流行应用程序的兼容性的程度对其进行评估。我们100%修复了之前工作中发现的应用程序内漏洞,占该工作中发现的全部安全漏洞的31.4%。此外,我们发现99.4%的Android应用程序和93.0%的Android应用程序分别兼容我们的发送和接收更改。
The complexity of Android's message-passing system has led to numerous vulnerabilities in third-party applications. Many of these vulnerabilities are a result of developers confusing inter-application and intra-application communication mechanisms. Consequently, we propose modifications to the Android platform to detect and protect inter-application messages that should have been intra-application messages. Our approach automatically reduces attack surfaces in legacy applications. We describe our implementation for these changes and evaluate it based on the attack surface reduction and the extent to which our changes break compatibility with a large set of popular applications. We fix 100% of intra-application vulnerabilities found in our previous work, which represents 31.4% of the total security flaws found in that work. Furthermore, we find that 99.4% and 93.0% of Android applications are compatible with our sending and receiving changes, respectively.