RoppDroid: Robust permission re-delegation prevention in Android inter-component communication.

Computers & Security(2017)

引用 8|浏览45
暂无评分
摘要
Abstract Android is designed such that Android applications (Apps) can provide functions to each other by providing a complex inter-component communication (ICC) model. While app interactions make it convenient and easy for one app to delegate functionality to another app, it also leads to permission re-delegation among Android apps which can cause privilege escalation. One approach taken by existing work tries to mitigate privilege escalation by enforcing tightened permissions. Unfortunately, preventing privilege escalation often renders the recipient apps unusable (for example, causing the app to crash). In this work, we propose another approach to address the privilege escalation problem from Android app ICC which intends to better preserve app functionality. We propose a context specific resource virtualization to eliminate privilege escalation by taking into account the interaction of ICCs among apps. We evaluated our prototype system, R opp D roid , on real-world Android apps and showed the effectiveness in providing robust protection for those apps. Our prototype also has low performance overheads.
更多
查看译文
关键词
Android,Inter-component communication,Permission re-delegation,Privilege escalation,Resource virtualization,Security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要