【24h】

Permission Analysis of Health and Fitness Apps in IoT Programming Frameworks

机译:物联网编程框架中健康和健身应用的权限分析

获取原文
获取原文并翻译 | 示例

摘要

Popular IoT programming frameworks, such as Google Fit, enable third-party developers to build apps to store and retrieve user data from a variety of data sources (e.g., wearables). The problem of overprivilege stands out due to the diversity and complexity of IoT apps, and developers rushing to release apps to meet the high demand in the IoT market. Any incorrect API usage of the IoT frameworks by third-party developers can lead to security risks, especially in health and fitness apps. Protecting sensitive user information is critically important to prevent financial and psychological harms. This paper presents PGFIT, a static permission analysis tool that precisely and efficiently identifies overprivilege issues in third-party apps built on top of a popular IoT programming framework, Google Fit. PGFIT extracts the set of requested permission scopes and the set of used data types in Google Fitenabled apps to determine whether the requested permission scopes are actually necessary. In this way, PGFIT serves as a quality assurance tool for developers and a privacy checker for app users. We used PGFIT to perform overprivilege analysis on a set of 20 Google Fit-enabled apps and with manual inspection, we found that 6 (30%) of them are overprivileged.
机译:流行的IoT编程框架(例如Google Fit)使第三方开发人员能够构建应用来存储和检索来自各种数据源(例如可穿戴设备)的用户数据。由于物联网应用程序的多样性和复杂性,超权限问题突出,开发人员争相发布应用程序以满足物联网市场的高需求。第三方开发人员对IoT框架的API使用不正确都会导致安全风险,尤其是在健康和健身应用中。保护敏感的用户信息对于防止财务和心理伤害至关重要。本文介绍了PGFIT,这是一种静态权限分析工具,可精确有效地识别基于流行的IoT编程框架Google Fit构建的第三方应用程序中的超权限问题。 PGFIT会在Google Fitenabled应用程序中提取一组请求的权限范围和一组使用的数据类型,以确定所请求的权限范围是否确实必要。这样,PGFIT可以为开发人员提供质量保证工具,并为应用程序用户提供隐私检查器。我们使用PGFIT对20个启用了Google Fit的应用程序进行了特权分析,并通过手动检查发现其中6个(30%)特权过高。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号