首页> 外文会议>IEEE International Conference on Trust, Security and Privacy in Computing and Communications >Evaluating the Trust of Android Applications through an Adaptive and Distributed Multi-criteria Approach
【24h】

Evaluating the Trust of Android Applications through an Adaptive and Distributed Multi-criteria Approach

机译:通过自适应和分布式多标准方法评估Android应用程序的信任

获取原文

摘要

New generation mobile devices, and their app stores, lack of a methodology to associate a level of trust to applications to faithfully represent their potential security risks. This problem is even more critical with newly published applications, for which either user reviews are missing or the number of downloads is still low. In this scenario, users may not fully estimate the risk associated with downloading apps found on on-line stores. Hence, here we propose a methodology for evaluating the trust level of an application through an adaptive, flexible, and dynamic framework. The evaluation of an application trust is performed using both static and dynamic parameters, which consider the application meta-data, its run-time behavior and the reports of users with respect to the software critical operations. We have validated the proposed approach by testing it on more than 180 real applications found both on official and unofficial markets by showing that it correctly categorizes applications as trusted or untrusted in 94% of the cases and it is resilient to poisoning attacks.
机译:新一代移动设备及其应用商店,缺乏将信任程度与应用程序联系起来忠实代表其潜在安全风险的方法。对于新发布的应用程序,此问题更为重要,其中缺少用户评论或下载的数量仍然很低。在这种情况下,用户可能无法完全估算与在线商店中的下载应用程序相关的风险。因此,在这里,我们提出了一种通过自适应,灵活和动态框架来评估应用程序的信任级别的方法。使用静态和动态参数执行应用程序信任的评估,该参数考虑应用程序元数据,其运行时行为以及用户对软件关键操作的报告。我们通过在官方和非官方市场上发现的超过180个真实应用程序来验证了所提出的方法,通过表明它将应用程序正确分类为94%的案例,它是有责任的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号