首页> 外文会议>International Conference on Computing, Networking and Communications >An effective access control scheme for preventing permission leak in Android
【24h】

An effective access control scheme for preventing permission leak in Android

机译:一种用于防止Android泄漏的有效访问控制方案

获取原文

摘要

In the Android system, each application runs in its own sandbox, and the permission mechanism is used to enforce access control to the system APIs and applications. However, permission leak could happen when an application without certain permission illegally gain access to protected resources through other privileged applications. We propose SPAC, a component-level system permission based access control scheme that can help developers better secure the public components of their applications. In the SPAC scheme, obscure custom permissions are replaced by explicit system permissions. We extend current permission checking mechanism so that multiple permissions are supported on component level. SPAC has been implemented on a Nexus 4 smartphone, and our evaluation demonstrates its effectiveness in mitigating permission leak vulnerabilities.
机译:在Android系统中,每个应用程序在其自己的沙箱中运行,并且权限机制用于强制对系统API和应用程序的访问控制。 但是,在没有某些权限的应用程序中通过非法通过其他特权应用程序访问受保护资源时,可能会发生权限泄漏。 我们提出SPAC,一种基于组件级系统权限的访问控制方案,可以帮助开发人员更好地保护其应用程序的公共组件。 在SPAC方案中,模糊的自定义权限由显式系统权限替换。 我们扩展了当前权限检查机制,以便在组件级别支持多个权限。 SPAC已在Nexus 4智能手机上实施,我们的评估表明其在减轻许可泄漏漏洞方面的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号