首页> 外文会议>IEEE International Symposium on Software Reliability Engineering Workshops >AppWrapper: Patching Security Functions with Dynamic Policy on Your Insecure Android Apps
【24h】

AppWrapper: Patching Security Functions with Dynamic Policy on Your Insecure Android Apps

机译:AppWrapper:在Insecure Android应用程序上修补安全功能,具有动态策略

获取原文

摘要

Android provides a security system with permission control, but there are a number of vulnerabilities that have excessive permission rights and a large number of per-permission related APIs. To address these vulnerabilities, permission control studies have been conducted on APIs that are at risk of compromising user privacy. However, it is impossible to add a new security function to an insecure application, and there is a disadvantage that an overhead occurs in the progress of the app because the user is required to permit permission in real time and the users' convenience is decreased. In this paper, we propose an AppWrapper toolkit. The toolkit can add security functions to the user/administrator's desired locations (method level in activities) of an insecure app using the appwrapping technique. And, using dynamic policy management, it is easy to apply secure policies without adding security functions again. In addition, by providing a real-time app log function that considers the convenience of users, it is possible to confirm the location where the security function is required according to the progress flow of the insecure app, and to create a policy file by setting the policy. Experiments on commercial apps have shown 100% success rate, except for apps with built-in security and Android apps. On the average, it took 1.86 seconds to add the security function through the proposed framework, and the file size increased by about 2.11%, indicating that the security function can be added in a short time with the increase of the minimum file size.
机译:Android提供具有权限控制的安全系统,但有许多漏洞具有过多的权限权限和大量的每个权限相关的API。为了解决这些漏洞,已在API上进行许可控制研究,这些研究有可能妥协用户隐私的风险。但是,不可能将新的安全功能添加到不安全的应用程序,并且存在缺点,即在应用程序的进度中发生开销,因为用户需要实时允许用户的权限,并且用户的便利性降低。在本文中,我们提出了一个AppWrapper Toolkit。使用AppPraping技术可以将安全功能添加到用户/管理员所需的Insecure应用程序的所需位置(活动中的方法级别)。并且,使用动态策略管理,很容易应用安全策略而不再次添加安全功能。此外,通过提供一种实时应用程序日志功能,它考虑了用户的便利性,可以根据不安全应用程序的进度流确认需要安全功能的位置,并通过设置创建策略文件政策。商业应用程序的实验显示了100%的成功率,除了带内置安全和Android应用程序的应用程序。在平均而言,通过建议的框架将安全功能添加1.86秒,文件大小增加了大约2.11%,表明可以在短时间内添加安全功能随着最小文件大小的增加。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号