跳到主要导航 跳到搜索 跳到主要内容

Contextual approach for identifying malicious Inter-Component privacy leaks in Android apps

  • Daojuan Zhang
  • , Yuanfang Guo
  • , Dianjie Guo
  • , Rui Wang
  • , Guangming Yu*
  • *此作品的通讯作者
  • CAS - Institute of Information Engineering
  • University of Chinese Academy of Sciences
  • Chinese Research Institute of General Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Inter-Component Communication (ICC) enables developers to create rich and innovative applications in Android platform. However, some privacy problems occur because of the interactions among multiple components. Since the flow of sensitive data across components may be legal or malicious, it is necessary to perform a precise ICC analysis to identify the malicious flow of sensitive data. In this paper, we propose a static taint analysis method, named IccChecker, to identify the malicious ICC-based privacy leaks in Android applications. IccChecker first tracks the potential flow of sensitive data across components and extracts the contextual factors which trigger the sensitive behavior. By leveraging the context information, our approach differentiates the malicious privacy leaks from the legal privacy information exchanges according to the proposed contextual policy. Moreover, we present a comprehensive assessment with benchmarks and real-world applications. Our evaluation results with benchmarks demonstrate that IccChecker improves the precision of ICC-based privacy leak detection. In the evaluation with real-world applications, our approach identifies 4 apps with ICC-based privacy leaks among 168 Google Play apps (2.3%) while 31 apps are identified from 49 malwares (63.3%).

源语言英语
主期刊名2017 IEEE Symposium on Computers and Communications, ISCC 2017
出版商Institute of Electrical and Electronics Engineers Inc.
228-235
页数8
ISBN(电子版)9781538616291
DOI
出版状态已出版 - 1 9月 2017
已对外发布
活动2017 IEEE Symposium on Computers and Communications, ISCC 2017 - Heraklion, 希腊
期限: 3 7月 20177 7月 2017

出版系列

姓名Proceedings - IEEE Symposium on Computers and Communications
ISSN(印刷版)1530-1346

会议

会议2017 IEEE Symposium on Computers and Communications, ISCC 2017
国家/地区希腊
Heraklion
时期3/07/177/07/17

指纹

探究 'Contextual approach for identifying malicious Inter-Component privacy leaks in Android apps' 的科研主题。它们共同构成独一无二的指纹。

引用此