首页> 外文会议>European Symposium on Research in Computer Security >Intentio Ex Machina: Android Intent Access Control via an Extensible Application Hook
【24h】

Intentio Ex Machina: Android Intent Access Control via an Extensible Application Hook

机译:Intentio Ex Machina:Android Intent Access Control通过可扩展应用程序挂钩

获取原文

摘要

Android's intent framework serves as the primary method for interprocess communication (IPC) among apps. The increased volume of intent IPC present in Android devices, coupled with intent's ability to implicitly find valid receivers for IPC, bring about new security challenges. We propose Intentio Ex Machina (IEM), an access control solution for Android intent security. IEM separates the logic for performing access control from the point of interception by placing an interface in the Android framework. This allows the access control logic to be placed inside a normal application and reached via the interface. The app, called a "user firewall", can then receive intents as they enter the system and inspect them. Not only can the user firewall allow or block intents, but it can even modify them to a controlled extent. Since it runs as a user application, developers are able to create user firewalls that manufacturers can then integrate into their devices. In this way, IEM allows for a new genre of security application for Android systems offering a creative and interactive approach to active IPC defense.
机译:Android的Intent Framework是应用程序之间的进程间通信(IPC)的主要方法。 Android设备中存在的INTINT IPC的增加量增加,耦合INTINTINTINTINTINTIVESIVEIVEITIVE IPC的有效接收器的能力,带来了新的安全挑战。我们提出Intentio Ex Machina(IEM),Android Intent安全的访问控制解决方案。 IEM将逻辑分开以通过在Android框架中放置接口来将访问控制执行访问控制。这允许访问控制逻辑放置在正常应用程序内并通过接口到达。该应用程序,称为“用户防火墙”,然后可以在进入系统时接收意图并检查它们。用户防火墙不仅可以允许或阻止意图,但甚至可以将它们修改为受控范围。由于它作为用户应用程序运行,因此开发人员能够创建制造商可以集成到其设备中的用户防火墙。通过这种方式,IEM允许为Android系统提供新的安全应用程序,为主动IPC防御提供创意和交互式方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号