计算机科学 ›› 2012, Vol. 39 ›› Issue (Z11): 16-18.

• 综述 • 上一篇    下一篇

基于静态数据流分析的Android应用权限检测方法

杨博 唐祝寿 朱浩谨 沈备军 林九川   

  1. (上海交通大学软件学院 上海 20O240)(公安部第三研究所 上海 201204)
  • 出版日期:2018-11-16 发布日期:2018-11-16

Method of Android Applications Permission Detection Based on Static Dataflow Analysis

  • Online:2018-11-16 Published:2018-11-16

摘要: 拥有Android关键资源使用权限的应用经常成为攻击者攻击的目标。而使用权限的申请完全是由应用完成 的,用户往往是盲目的接受。针对这种情况,提出了一种基于数据流分析的Android应用权限检测方法,设计和实现 了静态检测工具Brox,并对多个Android应用是否申请了过多的权限进行了检测。I3rox在检测的准确性和性能方面 都达到了令人满意的效果。

关键词: Android,权限,Randoop,数据流分析

Abstract: Android applications that have access to crucial system resources arc the targets of attackers. An application applies the access rights when it is installed, and users always ignore that. This paper proposes a new method to detect overprivilege in compiled Android applications,which leverages dataflow analysis to get the parameters of an API call. A static detection tool "Brox" is implemented based on this method. And 13rox is tested using multiply Android applica- lions. The test results on the accuracy and performance are quite encouraging.

Key words: Android, Permission, Randoop, Dataflow analysis

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!