首页> 外文会议>IEEE International Symposium on Software Reliability Engineering Workshops >Appwrapping Providing Fine-Grained Security Policy Enforcement Per Method Unit in Android
【24h】

Appwrapping Providing Fine-Grained Security Policy Enforcement Per Method Unit in Android

机译:打包为Android中的每个方法单元提供细粒度的安全策略实施

获取原文

摘要

Enterprise mobility management (EMM) solution is widely used to securely protect confidential information stored on an individual's smartphone, while increasing the efficiency because of BYOD policy. The application wrapping (Appwrapping) technology is one way to be applied EMM solutions, by modifying binary applications without the original source code. In the past, Appwrapping was performed to control permissions or APIs to protect privacy on Android. This method is applied collectively to the whole section, not a specific section of the app, so it is difficult to control the section (flow) desired by the user or the manager. In addition, system overhead can occur because the control is applied to the whole section of the app. In this paper, we propose a method to insert an additional security policy code at a certain interval position in the intermediate code of a binary app, so that it can be controlled at a specific interval rather than the whole interval of the app. The proposed method extracts and saves the security policy intermediate code and the related file in advance and then adds the security policy code to the specific method on the intermediate code of the specific activity acquired by decompiling the target app. Finally, the additional security policy code is modified to avoid errors caused by the additional code. We create an automation tool for performance verification, experiment with five commercial office apps, and confirm that the apps work properly with the added EMM security functions.
机译:企业移动管理(EMM)解决方案被广泛用于安全保护存储在个人智能手机上的机密信息,同时由于BYOD策略而提高了效率。应用程序包装(Appwrapping)技术是通过不使用原始源代码修改二进制应用程序而应用EMM解决方案的一种方法。过去,执行Appwrapping是为了控制权限或API,以保护Android上的隐私。此方法集中应用于整个部分,而不是应用程序的特定部分,因此很难控制用户或管理员所需的部分(流程)。此外,由于控件已应用到应用的整个部分,因此可能会发生系统开销。在本文中,我们提出了一种在二进制应用程序的中间代码中的特定间隔位置插入附加安全策略代码的方法,以便可以在特定间隔而不是整个应用程序间隔对其进行控制。提出的方法预先提取并保存安全策略中间代码和相关文件,然后将安全策略代码添加到通过反编译目标应用而获得的特定活动的中间代码上的特定方法上。最后,对附加安全策略代码进行修改,以避免由附加代码引起的错误。我们创建了一个用于性能验证的自动化工具,尝试了五个商用Office应用程序,并确认这些应用程序可通过添加的EMM安全功能正常运行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号