首页> 外文期刊>Concurrency and Computation >Towards a multilayered permission-based access control for extending Android security
【24h】

Towards a multilayered permission-based access control for extending Android security

机译:迈向基于权限的多层访问控制,以扩展Android安全性

获取原文
获取原文并翻译 | 示例

摘要

This paper discusses security issues on the user equipment, which is the “last mile” of socialrnnetworks. One of the main Achilles' heel of social networks is not the organization of networksrnthemselves, but the user devices, typically Android ones. The existing system of privilegesrnmakes it easy to infiltrate the network via applications installed on users' devices. Conventionalrnsignature-based and static analysis methods are vulnerable. Access to privacy- andrnsecurity-relevant parts of the application programming interface is controlled by the correspondingrnpermission in a manifest file.While requesting access to permissions, it may offer opportunitiesrnto malicious codes, which will cause security issues. Few works among permission analysis,rnhowever, pay attention to the prevention of permission leakage on both hardware and softwarernframeworks. In this paperwe tackle the challenge of providing our multilayered permission-basedrnsecurity extension scheme on Android platforms.We propose a usage and access control modelrnand an effective method of preventing permission leakage based on ARM TrustZone securityrnextension mechanism. In contrast to previous work, the proposed security architecture provides arnpermission-based mandatory access control on Androidmiddleware, Linux kernel, and hardwarernlayers.The evaluation results demonstrate the effectiveness of the proposed scheme in mitigatingrnpermission leakage vulnerabilities.
机译:本文讨论了用户设备上的安全性问题,这是社交网络的“最后一英里”。社交网络的主要致命弱点之一不是网络本身的组织,而是用户设备,通常是Android设备。现有的特权系统使通过安装在用户设备上的应用程序轻松渗透到网络中。传统的基于签名和静态的分析方法容易受到攻击。对应用程序编程接口中与隐私和安全性相关的部分的访问由清单文件中的相应权限控制。在请求访问权限时,它可能会提供恶意代码的机会,这将导致安全问题。权限分析中很少有工作,但是,要注意防止硬件和软件上的权限泄漏。在本文中,我们解决了在Android平台上提供基于权限的多层安全扩展方案的挑战。我们提出了一种使用和访问控制模型,以及一种基于ARM TrustZone安全性扩展机制的防止权限泄漏的有效方法。与以前的工作相比,该安全体系结构在Android中间件,Linux内核和硬件层上提供了基于权限的强制访问控制。评估结果证明了该方案在缓解权限泄漏漏洞方面的有效性。

著录项

  • 来源
    《Concurrency and Computation》 |2018年第5期|1-11|共11页
  • 作者单位

    State Key Laboratory of Mathematic Engineering and Advanced Computing, Zhengzhou, 450001, China;

    State Key Laboratory of Mathematic Engineering and Advanced Computing, Zhengzhou, 450001, China;

    Department of Computer, Zhejiang University, Hangzhou 310027, China;

    State Key Laboratory of Mathematic Engineering and Advanced Computing, Zhengzhou, 450001, China;

    School of Information Technology, Deakin University, Melbourne, VIC 3125, Australia;

    State Key Laboratory of Mathematic Engineering and Advanced Computing, Zhengzhou, 450001, China;

    State Key Laboratory of Mathematic Engineering and Advanced Computing, Zhengzhou, 450001, China;

    State Key Laboratory of Mathematic Engineering and Advanced Computing, Zhengzhou, 450001, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    access control; Android security,multilayered; permission; sandbox;

    机译:访问控制;Android安全性;多层;允许;沙盒;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号