【24h】

Android Permissions Unleashed

机译:释放了Android权限

获取原文

摘要

The Android Security Framework controls the executions of applications through permissions which are statically granted by the user during installation. However, the definition of security policies over permissions is not supported. Security policies must be therefore manually encoded into the application by the developer, which is a dangerous practice and may cause security breaches. We propose an improvement over the Android permission system that supports the specification and enforcement of fine-grained security policies. Enforcement is achieved by reducing policy decision problems to propositional satisfiability and leveraging a state-of-the-art SAT solver. Unlike alternative proposals, our approach does not require changes in the operating system and, therefore, it can be readily deployed in any commercial device.
机译:Android安全框架通过安装过程中用户静态授予的权限来控制应用程序的执行。但是,不支持通过权限定义安全策略。因此,开发人员必须将安全策略手动编码到应用程序中,这是一种危险的做法,并且可能导致安全漏洞。我们建议对Android权限系统进行改进,以支持细粒度安全策略的规范和实施。通过将政策决策问题减少到命题可满足性并利用最先进的SAT解算器来实现执行。与替代方案不同,我们的方法不需要更改操作系统,因此可以很容易地部署在任何商用设备中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号