首页> 外文会议>Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy >Droids in Disarray: Detecting Frame Confusion in Hybrid Android Apps
【24h】

Droids in Disarray: Detecting Frame Confusion in Hybrid Android Apps

机译:Droids在混乱中:检测混合动力Android应用中的帧混淆

获取原文

摘要

Frame Confusion is a vulnerability affecting hybrid applications which allows circumventing the isolation granted by the Same-Origin Policy. The detection of such vulnerability is still carried out manually by application developers, but the process is error-prone and often underestimated. In this paper, we propose a sound and complete methodology to detect the Frame Confusion on Android as well as a publicly-released tool (i.e., FCDroid) which implements such methodology and allows to detect the Frame Confusion in hybrid applications, automatically. We also discuss an empirical assessment carried out on a set of 50K applications using FCDroid, which revealed that a lot of hybrid applications suffer from Frame Confusion. Finally, we show how to exploit Frame Confusion on a news application to steal the user's credentials.
机译:帧混淆是影响混合应用的漏洞,其允许避免由同型原始策略授予的隔离。通过应用程序开发人员仍然手动进行这种漏洞的检测,但该过程易于出错并且通常低估。在本文中,我们提出了一种声音和完整的方法,可以检测Android上的帧混淆以及实现这种方法的公开发布的工具(即,FCDroid),并允许自动检测混合应用中的帧混淆。我们还讨论了使用FCDROID的一组50K应用中进行的实证评估,揭示了许多混合应用遭受框架混淆。最后,我们展示了如何利用新闻应用程序的帧混淆来窃取用户的凭据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号