...
首页> 外文期刊>Journal of information security and applications >Dynamic privacy leakage analysis of Android third-party libraries
【24h】

Dynamic privacy leakage analysis of Android third-party libraries

机译:Android第三方图书馆动态隐私泄漏分析

获取原文
获取原文并翻译 | 示例

摘要

The third-party libraries are reusable resources that are widely employed in Android Apps. While the third-party libraries provide a variety of functions, they bring serious security and privacy problems. The third-party libraries and the host Apps run in the same process and share the same permissions. Whether the third-party libraries are compliant with privacy policies is out of the control of App developers. In this work, we identify four types of privacy leakage paths inside Apps with case studies. Based on the Xposed framework, we propose a fine-grained and dynamic privacy-leakage analysis tool to analyze the privacy leakage behaviors of the third-party libraries in real time. Our tool can first identify the third-party libraries inside Apps, and then extracts call chains of the privacy source and sink functions during the execution of Apps, and finally evaluate the risks of privacy leaks of the third-party libraries according to the privacy leakage paths. We evaluate our tool over 150 popular Apps, collecting 1909 privacy data related call chains. We find that many third-party libraries access to private information. Moreover, they set up direct network connections to remote servers, which suggests that the third-party libraries pose a great privacy risk. The experiments results show that our tool can achieve real-time, fine-grained and dynamic privacy leakage analysis on Android Apps. (C) 2019 Elsevier Ltd. All rights reserved.
机译:第三方库是在Android应用程序中广泛使用的可重复使用的资源。虽然第三方图书馆提供了各种功能,但他们带来了严重的安全和隐私问题。第三方库和主机应用程序在同一进程中运行并共享相同的权限。是否符合隐私政策的第三方库是不受应用程序开发人员的控制。在这项工作中,我们在具有案例研究中确定了四种类型的隐私泄漏路径。基于XPOSED框架,我们提出了一种精细粗糙和动态的隐私泄漏分析工具,实时分析了第三方图书馆的隐私泄漏行为。我们的工具可以首先识别应用程序内的第三方库,然后在执行应用程序期间提取隐私源和宿函数的呼叫链,最后根据隐私泄露评估第三方库的隐私泄漏风险路径。我们在150多个流行应用程序中评估我们的工具,收集1909年隐私数据相关的呼叫链。我们发现许多第三方图书馆访问私人信息。此外,它们设置了与远程服务器的直接网络连接,这表明第三方库构成了很大的隐私风险。实验结果表明,我们的工具可以在Android应用程序上实现实时,细粒度和动态的隐私泄漏分析。 (c)2019 Elsevier Ltd.保留所有权利。

著录项

  • 来源
    《Journal of information security and applications 》 |2019年第6期| 259-270| 共12页
  • 作者单位

    Beijing Jiaotong Univ Beijing Key Lab Secur & Privacy Intelligent Trans Beijing 100044 Peoples R China;

    Beijing Jiaotong Univ Sch Comp & Informat Technol Beijing 100044 Peoples R China;

    Beijing Jiaotong Univ Sch Comp & Informat Technol Beijing 100044 Peoples R China;

    Beijing Jiaotong Univ Beijing Key Lab Secur & Privacy Intelligent Trans Beijing 100044 Peoples R China|Beijing Jiaotong Univ Sch Comp & Informat Technol Beijing 100044 Peoples R China;

  • 收录信息 美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Privacy leakage; Third-party library; Android Apps;

    机译:隐私泄漏;第三方图书馆;Android应用程序;
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号