...
首页> 外文期刊>Computers & Security >Prioritizing data flows and sinks for app security transformation
【24h】

Prioritizing data flows and sinks for app security transformation

机译:优先处理数据流和接收器以进行应用程序安全性转换

获取原文
获取原文并翻译 | 示例

摘要

There have been extensive investigations on identifying sensitive data flows in Android apps for detecting malicious behaviors. Typical real world apps have a large number of sensitive flows and sinks. Thus, security analysts need to prioritize these flows and data sinks according to their risks, i.e., flow ranking and sink ranking. In this paper, we present an efficient graph-algorithm based risk metric for prioritizing risky flows and sinks in Android grayware apps. The new risk metric is quantitative and can differentiate the sensitivities of flows and sinks in an app. In the experiments, our risk prioritization produces order-ings that are highly consistent with manual inspection. To enable post-detection security enforcement of sensitive sinks, we also present an automatic rewriting framework that utilizes the above prioritization technique. Our rewriting strategies are more feasible than the state-of-art solutions by supporting flow-and sink-based rewriting. We implement our prototype as ReDroid. ReDroid is designed for security analysts who manage organizational app repositories and customize third-party apps to satisfy organization imposed security requirements. We use ReDroid to rewrite both benchmark apps and real world gray-ware.
机译:在识别Android应用程序中的敏感数据流以检测恶意行为方面,已经进行了广泛的调查。典型的现实世界应用程序具有大量敏感的流量和接收器。因此,安全分析人员需要根据这些流和数据接收器的风险,即流等级和接收器等级,对它们进行优先级排序。在本文中,我们提出了一种基于图算法的有效风险度量标准,用于对Android灰色软件应用程序中的风险流和汇进行优先级划分。新的风险度量是定量的,可以区分应用程序中流量和汇的敏感性。在实验中,我们的风险优先级排序与人工检查高度一致。为了实现对敏感接收器的检测后安全实施,我们还提出了一种利用上述优先级排序技术的自动重写框架。通过支持基于流和接收器的重写,我们的重写策略比最新解决方案更可行。我们将原型实现为ReDroid。 ReDroid专为管理组织应用程序存储库并自定义第三方应用程序以满足组织施加的安全性要求的安全分析人员而设计。我们使用ReDroid重写基准测试应用程序和真实世界的灰色软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号