首页    期刊浏览 2024年07月05日 星期五
登录注册

文章基本信息

  • 标题:Prevention of cross-update privacy leaks on android
  • 本地全文:下载
  • 作者:Cho, Beumjin ; Lee, Sangho ; Xu, Meng
  • 期刊名称:Computer Science and Information Systems
  • 印刷版ISSN:1820-0214
  • 电子版ISSN:2406-1018
  • 出版年度:2018
  • 卷号:15
  • 期号:1
  • 页码:111-137
  • DOI:10.2298/CSIS170728047C
  • 出版社:ComSIS Consortium
  • 摘要:Updating applications is an important mechanism to enhance their availability, functionality, and security. However, without careful considerations, application updates can bring other security problems. In this paper, we consider a novel attack that exploits application updates on Android: a cross-update privacy-leak attack called COUPLE. The COUPLE attack allows an application to secretly leak sensitive data through the cross-update interaction between its old and new versions; each version only has permissions and logic for either data collection or transmission to evade detection. We implement a runtime security system, BREAKUP, that prevents cross-update sensitive data transactions by tracking permission-use histories of individual applications. Evaluation results show that BREAKUP’s time overhead is below 5%. We further show the feasibility of the COUPLE attack by analyzing the versions of 2;009 applications (28;682 APKs).
  • 关键词:android; privacy; information flow; permission
国家哲学社会科学文献中心版权所有