首页> 外文会议>2012 42nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks >An empirical study of the robustness of Inter-component Communication in Android
【24h】

An empirical study of the robustness of Inter-component Communication in Android

机译:Android中组件间通信的鲁棒性的实证研究

获取原文
获取原文并翻译 | 示例

摘要

Over the last three years, Android has established itself as the largest-selling operating system for smartphones. It boasts of a Linux-based robust kernel, a modular framework with multiple components in each application, and a security-conscious design where each application is isolated in its own virtual machine. However, all of these desirable properties would be rendered ineffectual if an application were to deliver erroneous messages to targeted applications and thus cause the target to behave incorrectly. In this paper, we present an empirical evaluation of the robustness of Inter-component Communication (ICC) in Android through fuzz testing methodology, whereby, parameters of the inter-component communication are changed to various incorrect values. We show that not only exception handling is a rarity in Android applications, but also it is possible to crash the Android runtime from unprivileged user processes. Based on our observations, we highlight some of the critical design issues in Android ICC and suggest solutions to alleviate these problems.
机译:在过去的三年中,Android已确立为最畅销的智能手机操作系统。它拥有基于Linux的强大内核,在每个应用程序中具有多个组件的模块化框架以及一个注重安全性的设计,其中每个应用程序都隔离在其自己的虚拟机中。但是,如果应用程序将错误的消息传递给目标应用程序并导致目标程序行为不正确,则所有这些期望的属性都将失效。在本文中,我们通过模糊测试方法对Android中组件间通信(ICC)的鲁棒性进行了实证评估,从而将组件间通信的参数更改为各种不正确的值。我们证明,不仅异常处理在Android应用程序中很少见,而且还可能使非特权用户进程导致Android运行时崩溃。根据我们的观察,我们重点介绍了Android ICC中的一些关键设计问题,并提出了缓解这些问题的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号