An Android Security Policy Enforcement Tool

被引:2
作者
Cotterell, Kathryn
Welch, Ian [1 ]
Chen, Aaron [1 ]
机构
[1] Victoria Univ, Sch Engn & Comp Sci, Wellington, New Zealand
关键词
mobile computing; !text type='Java']Java[!/text; Android; security;
D O I
10.1515/eletel-2015-0040
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The Android operating system (OS) has become the dominant smart phone OS in recent years due to its accessibility, usability and its open-source philosophy. Consequently, this has also made it a popular target for attackers who aim to install malware on Android devices and take advantage of Android's coarse-grained, non-revoking permission system. This project designs, implements and evaluates a security tool named COMBdroid, which addresses these security concerns in Android by enforcing fine-grained, user-defined policies. COMBdroid modifies an application before installation, allowing it to override points of security vulnerabilities at run-time. As a proof of concept we have implemented three policies in COMBdroid. This paper documents the development process of COMBdroid, deriving design decisions from the literature review, detailing the design and implementation, and proving the program's effectiveness through evaluation.
引用
收藏
页码:311 / 320
页数:10
相关论文
共 22 条
[1]  
Alll B., TOOL REVERSE ENG AND
[2]  
Bickford J., 2010, P 11 WORKSH MOB COMP, P4954
[3]  
Castillo C. A., 2010, ANDROID MALWARE PRES
[4]  
Conti M., 2011, P 13 INT C INF SEC S
[5]  
Davi L., 2011, P 13 INT C INF SEC S
[6]  
Dietz M., 2011, P 20 USENIX C SEC SE, P2323
[7]  
Enck W., 2009, P 16 ACM C COMP COMM
[8]  
Enck W., 2010, P 9 USENIX C OP SYST, P16
[9]  
Enck W., 2008, TECH REP
[10]  
Erturk E., 2012, CASE STUDY OPEN SOUR