【24h】

An Adaptive Android Security Extension against Privilege Escalation Attacks

机译:针对特权升级攻击的自适应Android安全扩展

获取原文
获取原文并翻译 | 示例

摘要

Android is the world's most popular mobile platform. Nevertheless, in spite of continuous efforts on its permission system, it is still incapable of resisting privilege escalation attacks, specially, the confused deputy attacks on numerous poor-designed applications. Worse yet, most existing security solutions become costly or rigid in recent Android dynamic permission environment. In this paper, we proposed a flexible and efficient security extension to Android middleware for protecting the vulnerable privileged applications from being abused by malwares in the dynamic permission scenario. Our framework maintains fresh permission states of applications at runtime and enforces access control on inter-component communications conservatively by checking the capability differences between applications, so as to provide more precise and temperate protection for applications. Moreover, we also introduced an efficient cache mechanism together with an optimized proactive updating method for decisions, which contributes significantly to improving the inspection efficiency. Finally, experimental results reveal that our framework is effective and adaptable in defending against confused deputy attacks on applications with negligible overhead and limited impact on application usability.
机译:Android是世界上最受欢迎的移动平台。但是,尽管在许可系统上进行了不断的努力,但它仍然无法抵抗特权提升攻击,特别是对众多设计欠佳的应用程序的混淆性副攻击。更糟糕的是,大多数现有的安全解决方案在最近的Android动态权限环境中变得昂贵或僵化。在本文中,我们提出了对Android中间件的灵活高效的安全扩展,以保护易受攻击的特权应用程序在动态权限情况下不被恶意软件滥用。我们的框架在运行时维护应用程序的新许可状态,并通过检查应用程序之间的功能差异来保守地执行组件间通信的访问控制,从而为应用程序提供更精确和温和的保护。此外,我们还引入了有效的缓存机制以及优化的决策主动更新方法,这极大地提高了检查效率。最后,实验结果表明,我们的框架可有效且适用于防御对应用程序的混淆副攻击,且开销可忽略不计,并且对应用程序可用性的影响有限。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号