首页> 外文期刊>Computers & Security >RoppDroid: Robust permission re-delegation prevention in Android inter-component communication
【24h】

RoppDroid: Robust permission re-delegation prevention in Android inter-component communication

机译:RoppDroid:Android组件间通信中强大的权限重新授权预防

获取原文
获取原文并翻译 | 示例
           

摘要

Android is designed such that Android applications (Apps) can provide functions to each other by providing a complex inter-component communication (ICC) model. While app interactions make it convenient and easy for one app to delegate functionality to another app, it also leads to permission re-delegation among Android apps which can cause privilege escalation. One approach taken by existing work tries to mitigate privilege escalation by enforcing tightened permissions. Unfortunately, preventing privilege escalation often renders the recipient apps unusable (for example, causing the app to crash). In this work, we propose another approach to address the privilege escalation problem from Android app ICC which intends to better preserve app functionality. We propose a context specific resource virtualization to eliminate privilege escalation by taking into account the interaction of ICCs among apps. We evaluated our prototype system, RoppDroid, on real-world Android apps and showed the effectiveness in providing robust protection for those apps. Our prototype also has low performance overheads.
机译:Android的设计使Android应用程序(Apps)可以通过提供复杂的组件间通信(ICC)模型相互提供功能。虽然应用程序交互使一个应用程序将功能委派给另一个应用程序变得方便,容易,但它也导致Android应用程序之间的权限重新授权,这可能导致特权升级。现有工作采用的一种方法试图通过加强严格的权限来减轻特权升级。不幸的是,阻止特权提升通常会使收件人应用程序无法使用(例如,导致应用程序崩溃)。在这项工作中,我们提出了另一种方法来解决Android应用ICC的特权提升问题,该方法旨在更好地保留应用功能。我们提出了一种特定于上下文的资源虚拟化,以通过考虑应用之间ICC的交互来消除特权升级。我们在真实的Android应用程序上评估了原型系统RoppDroid,并证明了为这些应用程序提供强大保护的有效性。我们的原型还具有较低的性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号