首页> 外文会议>IEEE International Conference on Computer and Communications >Secure HybridApp: A detection method on the risk of privacy leakage in HTML5 hybrid applications based on dynamic taint tracking
【24h】

Secure HybridApp: A detection method on the risk of privacy leakage in HTML5 hybrid applications based on dynamic taint tracking

机译:Secure HybridApp:一种基于动态污点跟踪的HTML5混合应用程序中隐私泄露风险的检测方法

获取原文

摘要

In the past few years, HTML5-based mobile applications are becoming more and more popular because they can run across different platforms, which greatly reduces the developing cost and improves the production efficiency. This kind of app is also called hybrid app. It can access the platform resources mostly like a native app with the help of many third-party frameworks. As we all know, web apps are prone to many kinds of attacks which can cause privacy leakage. HTML5 apps are a kind of web app, which means they can also be attacked by these web attacking methods. Due to the dynamic nature of hybrid apps, it is very hard to analyze the malicious behavior in them based on static or dynamic code analysis. But dynamic taint tracking method is very suitable for this task, it treats the user privacy as taint data and check whether it will be leaked out through illegal channels. Once this kind of action is found, we can stop it immediately and notice the app user about it. In this paper, we mainly talk about the privacy data, the privacy leakage channels in HTML5 hybrid apps. And we propose a dynamic method to avoid privacy leakage based on dynamic taint tracking in Android. It can be applied to other systems.
机译:在过去的几年中,基于HTML5的移动应用程序可以跨不同的平台运行,因此变得越来越流行,这大大降低了开发成本并提高了生产效率。这种应用也称为混合应用。在许多第三方框架的帮助下,它可以像访问本机应用程序一样访问平台资源。众所周知,Web应用程序容易受到多种攻击,这些攻击可能导致隐私泄露。 HTML5应用程序是一种Web应用程序,这意味着它们也可以被这些Web攻击方法攻击。由于混合应用程序具有动态特性,因此很难基于静态或动态代码分析来分析混合应用程序中的恶意行为。但是动态污点跟踪方法非常适合此任务,它将用户隐私视为污点数据,并检查其是否会通过非法渠道泄漏出去。一旦找到此类操作,我们可以立即将其停止并通知应用程序用户有关此操作。在本文中,我们主要讨论HTML5混合应用程序中的隐私数据,隐私泄漏渠道。并提出了一种基于Android动态污点跟踪的避免隐私泄露的动态方法。它可以应用于其他系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号