首页> 外文会议>Annual IFIP WG 11.3 conference on data and applications security and privacy >Quantitative Security Risk Assessment of Android Permissions and Applications
【24h】

Quantitative Security Risk Assessment of Android Permissions and Applications

机译:Android权限和应用程序的定量安全风险评估

获取原文

摘要

The booming of the Android platform in recent years has attracted the attention of malware developers. However, the permissions-based model used in Android system to prevent the spread of malware, has shown to be ineffective. In this paper, we propose DroidRisk, a framework for quantitative security risk assessment of both Android permissions and applications (apps) based on permission request patterns from benign apps and malware, which aims to improve the efficiency of Android permission system. Two data sets with 27,274 benign apps from Google Play and 1,260 Android malware samples were used to evaluate the effectiveness of DroidRisk. The results demonstrate that DroidRisk can generate more reliable risk signal for warning the potential malicious activities compared with existing methods. We show that DroidRisk can also be used to alleviate the overprivilege problem and improve the user attention to the risks of Android permissions and apps.
机译:近年来,Android平台的蓬勃发展吸引了恶意软件开发人员的注意力。但是,Android系统中用于防止恶意软件传播的基于权限的模型显示效果不佳。在本文中,我们提出了DroidRisk,这是一个基于来自良性应用程序和恶意软件的权限请求模式对Android权限和应用程序(应用程序)进行定量安全风险评估的框架,旨在提高Android权限系统的效率。两个数据集包含来自Google Play的27,274个良性应用程序和1,260个Android恶意软件样本,用于评估DroidRisk的有效性。结果表明,与现有方法相比,DroidRisk可以生成更可靠的风险信号来警告潜在的恶意活动。我们证明,DroidRisk还可以用于缓解过度特权问题并提高用户对Android权限和应用程序风险的关注。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号