首页> 外文会议>International Conference on Mobile Ad-hoc and Sensor Networks >VDetector: Detecting Vulnerability Based on Inter-Component Data Flows in Android Applications
【24h】

VDetector: Detecting Vulnerability Based on Inter-Component Data Flows in Android Applications

机译:VDetector:基于组件间数据流的漏洞检测Android应用程序中的漏洞

获取原文

摘要

With the popularity of Android devices and the improvement of intelligence of mobile phones, our life becomes more and more convenient. Meanwhile, the popularity brings new challenges to Android security, especially the application vulnerabilities. These vulnerabilities may lead to sensitive data leaks. To address this issue, researchers have proposed methods to detect the vulnerabilities in Android applications. But most of them only detect one type of vulnerabilities. In this paper, we propose VDetector, a data flow tracking based method for detecting three types of vulnerabilities, Log Leak Vulnerability, Content Provider Vulnerability, and Inter-Components Communication Vulnerability. Based on the reasons of the three types of vulnerabilities, VDetector transforms the detection into the data flow tracking. We first extend the source and sink sets corresponding to the vulnerabilities. Then we explore whether there are paths between the sources and the sinks. If there are paths, it indicates that the vulnerabilities exist. At last, three datasets are used for experiments and the result indicates that VDetector effectively finds such android application vulnerabilities above.
机译:随着Android设备的普及和移动电话智能的改进,我们的生活变得越来越方便。同时,人气为Android Security提供了新的挑战,尤其是应用漏洞。这些漏洞可能导致敏感的数据泄漏。为了解决这个问题,研究人员提出了检测Android应用程序中漏洞的方法。但大多数人只检测一种类型的漏洞。在本文中,我们提出了基于数据流跟踪的数据流跟踪,用于检测三种类型的漏洞,日志泄漏漏洞,内容提供商漏洞和组件间通信漏洞的方法。基于三种类型的漏洞的原因,VDetector将检测转换为数据流跟踪。我们首先扩展与漏洞对应的源和汇集。然后我们探索是否存在源和水槽之间的路径。如果有路径,则表示存在漏洞。最后,三个数据集用于实验,结果表明VDetector有效地找到了上面的Android应用程序漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号