首页> 外文会议>International Conference on Computer, Network, Communication and Information Systems >A Static Detection of Inter-Component Communication Vulnerability in Android Application
【24h】

A Static Detection of Inter-Component Communication Vulnerability in Android Application

机译:Android应用程序中组件间通信漏洞的静态检测

获取原文

摘要

Security issues were found between inter-component communication in Android application: the usage of explicit or implicit intent might give rise to data attack, component hijacking and privilege escalation, etc. in order to detect these problems, a detect method of inter-component communication vulnerability on Android application was presented. Firstly, an APK was analyzed reversely, and ICC methods in its component were detected. Afterwards, its component call pair, component call link and component call graph were constructed. Next, the detect framework began to analyze data flow of the suspicious components. Experimental results show that the proposed method is able to detect common inter-component communication vulnerability comprehensively and effectively not only between different components but also different applications.
机译:在Android应用程序中组件间通信之间发现了安全问题:显式或隐式意图的使用可能会导致数据攻击,组件劫持和特权等。为了检测这些问题,是组件间通信的检测方法提出了Android应用程序的漏洞。首先,逆转分析APK,并检测其组分中的ICC方法。之后,构造了其组件调用对,组件调用链路和组件调用图。接下来,检测框架开始分析可疑组件的数据流。实验结果表明,该方法能够全面地检测常见的组件间通信脆弱性,不仅可以在不同的组件之间综合,有效地检测,而且有效地检测不同的组件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号