首页> 外文会议>International Conference on Computer Science and Service System;CSSS 2012 >Android Permission Re-delegation Detection and Test Case Generation
【24h】

Android Permission Re-delegation Detection and Test Case Generation

机译:Android权限重新授权检测和测试用例生成

获取原文

摘要

As smart phones are becoming widespread over the world, relevant security problems emerge. On Android platform, some applications are granted to access some restrictive resources via system APIs. Such applications may expose this capability to the other applications without certain permissions. This will lead to permission re-delegation attacks. In this paper, we describe how this vulnerability occurs on Android through inter-process communication (IPC). We focus on a major IPC channel in Android operating system, the intent based IPC. In order to help developers decrease the possibility of their applications to be attacked, we present a static analysis tool Diordna in this paper. Diordna works on Java byte codes and finds out possible permission re-delegations from public entry points of applications. Diordna also leverages a dataflow analysis to generate intent oriented test case specifications, namely, to infer what should be contained in an intent object by which the target application will re-delegate its granted permissions. We have experimented our solution and Diordna on two pre-installed Android applications and it generates reasonable test case specifications that can be used to write testing programs.
机译:随着智能电话在世界范围内的普及,出现了相关的安全问题。在Android平台上,某些应用程序被授予通过系统API访问某些限制性资源的权限。此类应用程序可能在没有某些权限的情况下向其他应用程序公开此功能。这将导致权限重新授权攻击。在本文中,我们描述了如何通过进程间通信(IPC)在Android上发生此漏洞。我们专注于Android操作系统中的主要IPC渠道,即基于意图的IPC。为了帮助开发人员减少其应用程序受到攻击的可能性,我们在本文中提供了一种静态分析工具Diordna。 Diordna处理Java字节码,并从应用程序的公共入口点查找可能的权限重新授权。 Diordna还利用数据流分析来生成面向意图的测试用例规范,即,推断意图对象中应包含的内容,目标应用程序将通过该意图重新授予其授予的权限。我们已经在两个预装的Android应用程序上对我们的解决方案和Diordna进行了实验,它生成了合理的测试用例规范,可用于编写测试程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号