首页> 外文会议>IEEE International Conference on Computer and Communications >Secure HybridApp: A detection method on the risk of privacy leakage in HTML5 hybrid applications based on dynamic taint tracking
【24h】

Secure HybridApp: A detection method on the risk of privacy leakage in HTML5 hybrid applications based on dynamic taint tracking

机译:安全HybridApp:基于动态Taint跟踪的HTML5混合应用中隐私泄漏风险的检测方法

获取原文

摘要

In the past few years, HTML5-based mobile applications are becoming more and more popular because they can run across different platforms, which greatly reduces the developing cost and improves the production efficiency. This kind of app is also called hybrid app. It can access the platform resources mostly like a native app with the help of many third-party frameworks. As we all know, web apps are prone to many kinds of attacks which can cause privacy leakage. HTML5 apps are a kind of web app, which means they can also be attacked by these web attacking methods. Due to the dynamic nature of hybrid apps, it is very hard to analyze the malicious behavior in them based on static or dynamic code analysis. But dynamic taint tracking method is very suitable for this task, it treats the user privacy as taint data and check whether it will be leaked out through illegal channels. Once this kind of action is found, we can stop it immediately and notice the app user about it. In this paper, we mainly talk about the privacy data, the privacy leakage channels in HTML5 hybrid apps. And we propose a dynamic method to avoid privacy leakage based on dynamic taint tracking in Android. It can be applied to other systems.
机译:在过去几年中,基于HTML5的移动应用程序变得越来越受欢迎,因为它们可以跨越不同的平台运行,这大大降低了开发成本并提高了生产效率。这种应用程序也被称为Hybrid应用程序。在许多第三方框架的帮助下,它可以访问平台资源大多数原生应用程序。众所周知,Web应用程序易于多种可能导致隐私泄漏的攻击。 HTML5应用程序是一种Web应用程序,这意味着它们也可以被这些Web攻击方法攻击。由于混合应用程序的动态性质,很难根据静态或动态码分析分析它们中的恶意行为。但动态Taint跟踪方法非常适合此任务,它将用户隐私视为Taint数据,并检查是否通过非法渠道泄露。一旦找到这种行动,我们就可以立即停止并注意到应用程序用户。在本文中,我们主要讨论隐私数据,HTML5混合应用程序中的隐私泄漏频道。我们提出了一种动态的方法,以避免基于Android的动态污染跟踪的隐私泄漏。它可以应用于其他系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号