原文传递 Automated Android Application Partitioning (A3P).
题名: Automated Android Application Partitioning (A3P).
作者: Jordan, A.; Spina, M.; Clough, B.; Sirois, K.; Zakhalyavko, M.
关键词: Mobile application software, Mobile devices, Computer network security, Distributed computing, Reasoning, Mobile operating systems, Mobile phones, Android, Permission, Software reusability
摘要: Mobile applications have become ubiquitous and a critical part of many peoples every-day life. However, mobile operating systems provide only coarse control over how private data is accessed, transformed, or used, and users have remarkably little understanding of how this can affect their privacy. Complicating matters further are advertising libraries or other third-party software that require odd permissions in order to satisfy their particular needs, but are tangential to the main application. To address these issues, we present a system for analyzing an Android applications control flow, information flow, and security profile to partition it into a set of cooperating reduced-privilege micro-apps that reproduce the original applications functionality. Our experiments on real-world applications indicate that this approach provides significant value in reducing the security requirements of an individual micro-app, and that the original application functionality can be reproduced by the collection of micro-apps.
报告类型: 科技报告
检索历史
应用推荐