跳到主要导航 跳到搜索 跳到主要内容

Privilege Leakage and Information Stealing through the Android Task Mechanism

  • Yinhao Xiao
  • , Guangdong Bai
  • , Jian Mao
  • , Zhenkai Liang
  • , Wei Cheng
  • George Washington University
  • Singapore Institute of Technology
  • National University of Singapore
  • Virginia Commonwealth University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

To facilitate apps to collaborate in finish complex jobs, Android allows isolated apps to communicate through explicit interfaces. However, the communication mechanisms often give additional privilege to apps, which can be exploited by attackers. The Android Task Structure is a widely-used mechanism to facilitate apps' collaboration. Recent research has identified attacks to the mechanism, allowing attackers to spoof UIs in Android. In this paper, we present an analysis on the security of Android task structure. In particular, we analyze the system/app conditions that can cause the task mechanism to leak privilege. Furthermore, we identify new end-to-end attacks that enable attackers to actively interfere with victim apps to steal sensitive information. Based on our findings, we also develop atask interference checking app for exploits to the Android task structure.

源语言英语
主期刊名Proceedings - 2017 IEEE Symposium on Privacy-Aware Computing, PAC 2017
出版商Institute of Electrical and Electronics Engineers Inc.
152-163
页数12
ISBN(电子版)9781538610275
DOI
出版状态已出版 - 4 12月 2017
活动1st IEEE Symposium on Privacy-Aware Computing, PAC 2017 - Washington, 美国
期限: 1 8月 20173 8月 2017

出版系列

姓名Proceedings - 2017 IEEE Symposium on Privacy-Aware Computing, PAC 2017
2017-January

会议

会议1st IEEE Symposium on Privacy-Aware Computing, PAC 2017
国家/地区美国
Washington
时期1/08/173/08/17

学术指纹

探究 'Privilege Leakage and Information Stealing through the Android Task Mechanism' 的科研主题。它们共同构成独一无二的学术指纹。

引用此