Skip to main navigation Skip to search Skip to main content

Automatic permission inference for hybrid mobile apps

  • Jian Mao*
  • , Hanjun Ma
  • , Yue Chen
  • , Yaoqi Jia
  • , Zhenkai Liang
  • *Corresponding author for this work
  • Beihang University
  • National University of Singapore

Research output: Contribution to journalArticlepeer-review

Abstract

The application permission system is one of the key components of Android security. Developers often use it incorrectly and claim more permissions than necessary, due to limitations of developers' knowledge and development tools. When application's vulnerabilities are exploited, the additional permissions give attackers more capability to carry out attacks. Hybrid mobile applications (apps) are a class of mobile apps that are built from web technologies, such as HTML, JavaScript, and CSS. In such applications, it is often easier to inject third-party code through vulnerabilities. When developers do not specify app's permissions correctly, the injected code will result in dangerous actions breaching system security. In this paper, we develop an automatic tool to assist developers to identify the permissions required by the apps based on the hybrid mobile apps' runtime permission checking.

Original languageEnglish
Pages (from-to)55-64
Number of pages10
JournalJournal of High Speed Networks
Volume22
Issue number1
DOIs
StatePublished - 10 Feb 2016

Keywords

  • Android
  • Hybrid mobile app
  • automatic tool
  • permission
  • security

Fingerprint

Dive into the research topics of 'Automatic permission inference for hybrid mobile apps'. Together they form a unique fingerprint.

Cite this