首页> 外文会议>IEEE International Conference on Advanced Computing >Detection of Vulnerabilities Caused by WebView Exploitation in Smartphone
【24h】

Detection of Vulnerabilities Caused by WebView Exploitation in Smartphone

机译:检测由智能手机中的WebView开发引起的漏洞

获取原文

摘要

WebView is an essential component in Smartphone platforms, which enables the Smartphone applications (apps) to embed a simple yet powerful web browser inside them. In addition, it also enables rich interactions between apps and the web pages that are loaded on the WebView. To achieve this interaction, WebView provides a number of APIs that allow code in apps to invoke and be invoked by the JavaScript code within the web pages and to intercept and modify the events that occur within the web pages. With the help of these rich features, apps can become customized browsers for their intended web applications. However, the design of WebView changes the landscape of the Web, especially from the security perspective. Two essential components of the Web's security infrastructure are the Trusted Computing Base (TCB) and the sandbox protection. These are weakened upon the usage of WebView and its associated APIs. As a result, malicious attacks can be launched either against the apps or by the apps through the usage of WebView. The objective of this work is to explore and demonstrate such malicious attacks and to build a system that performs automated static analysis on apps for detecting WebView related vulnerabilities.
机译:WebView是Smartphone平台中必不可少的组件,它使Smartphone应用程序(应用程序)可以在其中嵌入简单但功能强大的Web浏览器。此外,它还支持应用程序与WebView上加载的网页之间的丰富交互。为了实现这种交互,WebView提供了许多API,这些API允许应用程序中的代码在网页内调用JavaScript代码并由JavaScript代码调用,并拦截和修改网页内发生的事件。借助这些丰富的功能,应用程序可以成为其预期的Web应用程序的自定义浏览器。但是,WebView的设计改变了Web的格局,尤其是从安全性角度而言。 Web安全基础结构的两个基本组成部分是可信计算库(TCB)和沙箱保护。使用WebView及其关联的API会削弱这些功能。结果,可以通过使用WebView对应用程序或由应用程序发起恶意攻击。这项工作的目的是探索和演示这种恶意攻击,并构建一个对应用程序执行自动静态分析以检测与WebView相关的漏洞的系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号