首页> 外文会议>International conference on trust and trustworthy computing >AndroidLeaks: Automatically Detecting Potential Privacy Leaks in Android Applications on a Large Scale
【24h】

AndroidLeaks: Automatically Detecting Potential Privacy Leaks in Android Applications on a Large Scale

机译:AndroidLeaks:大规模自动检测Android应用程序中的潜在隐私泄漏

获取原文

摘要

As mobile devices become more widespread and powerful, they store more sensitive data, which includes not only users' personal information but also the data collected via sensors throughout the day. When mobile applications have access to this growing amount of sensitive information, they may leak it carelessly or maliciously. Google's Android operating system provides a permissions-based security model that restricts an application's access to the user's private data. Each application statically declares the sensitive data and functionality that it requires in a manifest, which is presented to the user upon installation. However, it is not clear to the user how sensitive data is used once the application is installed. To combat this problem, we present AndroidLeaks, a static analysis framework for automatically finding potential leaks of sensitive information in Android applications on a massive scale. AndroidLeaks drastically reduces the number of applications and the number of traces that a security auditor has to verify manually. We evaluate the efficacy of AndroidLeaks on 24,350 Android applications from several Android markets. AndroidLeaks found 57,299 potential privacy leaks in 7,414 Android applications, out of which we have manually verified that 2,342 applications leak private data including phone information, GPS location, WiFi data, and audio recorded with the microphone. AndroidLeaks examined these applications in 30 hours, which indicates that it is capable of scaling to the increasingly large set of available applications.
机译:随着移动设备变得越来越普及和强大,它们存储了更多敏感数据,其中不仅包括用户的个人信息,还包括一整天通过传感器收集的数据。当移动应用程序可以访问数量不断增长的敏感信息时,它们可能会不经意或恶意泄漏信息。 Google的Android操作系统提供了基于权限的安全模型,该模型限制了应用程序对用户私人数据的访问。每个应用程序都在清单中静态声明其所需的敏感数据和功能,清单在安装时会显示给用户。但是,用户尚不清楚一旦安装了应用程序,将如何使用敏感数据。为了解决这个问题,我们提出了AndroidLeaks,这是一个静态分析框架,用于自动大规模发现Android应用程序中敏感信息的潜在泄漏。 AndroidLeaks大大减少了安全审核员必须手动验证的应用程序数量和跟踪数量。我们评估了AndroidLeaks在来自多个Android市场的24,350个Android应用程序上的功效。 AndroidLeaks在7,414个Android应用程序中发现了57,299个潜在的隐私泄漏,其中我们已经手动验证了2,342个应用程序泄漏了私人数据,包括电话信息,GPS位置,WiFi数据以及用麦克风录制的音频。 AndroidLeaks在30小时内检查了这些应用程序,这表明它能够扩展到越来越多的可用应用程序集。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号