Back to Search Start Over

Practical static analysis of detecting intent-based permission leakage in Android application

Authors :
Wei Cao
Bo Jin
Yong Zhang
Songyang Wu
Source :
2017 IEEE 17th International Conference on Communication Technology (ICCT).
Publication Year :
2017
Publisher :
IEEE, 2017.

Abstract

The permission model is an essential Android mechanism for resisting security threats: android malware can do very little if the user denies its requests for permissions. However, the recent literatures show that certain vulnerable applications with insufficiently enforced privileges may lead to critical permissions leakage via inter-application interaction. Malicious applications can trick these vulnerable applications to perform actions that are beyond their given privileges. This study proposes an efficient approach for the analysis of permission leakage vulnerabilities in Android inter-process communications; this approach identifies suspicious vulnerable paths based on an analysis of control-flow and dataflow. We handle the unsafe control flows over inter-component communication and asynchronous calls through Android callbacks, which is the major difference from previous related studies. The proposed system was evaluated using 550 real-world Android applications and the experiment result demonstrated the practicality of our method.

Details

Database :
OpenAIRE
Journal :
2017 IEEE 17th International Conference on Communication Technology (ICCT)
Accession number :
edsair.doi...........d1be6a60ac849d9ab607b0ef10ae4d64
Full Text :
https://doi.org/10.1109/icct.2017.8359970