首页> 外文会议>International Conference on Mobile and Secure Services >CoSINcheck to protect users from installing potentially harmful Android applications
【24h】

CoSINcheck to protect users from installing potentially harmful Android applications

机译:Cosincheck以保护用户安装可能有害的Android应用程序

获取原文
获取外文期刊封面目录资料

摘要

Android inherited its core security from the Linux operating system where applications run with different unique system identities. Another level of security based on “permission” model is present in Android, for controlling the accessibility of resources and operations that a given process can execute. Applications with no explicit permission request should not be able to influence the user experience or make use of any data on the device. The permissions are divided into normal and dangerous categories. Normal permission only needs to be statically declared in the manifest file and will be granted to the application during installation whereas dangerous permission requires further validation from the user when the application process is requesting it. Nevertheless, after the application installation, identifying whether personal data are used for the expected functionality or a malicious purpose is yet an unsolved problem. In brief, the user has no other choice than judging and trusting the application based on the developers' reputation. However, an application package used for installing an Android application can easily be refactored by a third party, which might damage the notoriety of the developers and put the users at risk. To address this problem, we present CoSINcheck, a client and server analysis framework for flagging potential refactored applications prior and after its installation on a device. Code, Signatures, Icons and Names are used as features in our detection system.
机译:从Android的Linux操作系统,其中应用程序具有不同的独特的系统运行的身份继承其核心的安全。基于“许可”模式的安全级别是目前Android中,控制资源和操作一个给定的进程可以执行的可访问性。没有明确的许可请求的应用程序不应该能够影响用户体验或使用设备上的任何数据。这些权限分为正常和危险类别。普通许可,只需要在清单文件中静态声明和而危险的权限需要从当应用程序请求它的用户进一步验证安装过程中将授予应用程序。然而,应用程序安装后,确定个人数据是否被用于预期的功能或恶意的目的又是一个未解决的问题。简单地说,用户没有其他选择判断和信任基础上开发者的声誉应用。然而,用于安装一个Android应用程序的应用程序包可以很容易地通过第三方,这可能会损害开发商的恶名,把用户处于危险之中重构。为了解决这个问题,我们目前CoSINcheck,检举潜在的客户端和服务器的分析框架重构应用程序之前,其在设备上安装之后。代码,签名,图标和名称被用作我们的检测系统功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号