Detecting Stubborn Permission Requests in Android Applications

被引:2
|
作者
Huang, Jianmeng [1 ]
Huang, Wenchao [1 ]
Miao, Fuyou [1 ]
Xiong, Yan [1 ]
机构
[1] Univ Sci & Technol China, Sch Comp Sci & Technol, Hefei, Anhui, Peoples R China
来源
2018 4TH INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING AND COMMUNICATIONS (BIGCOM 2018) | 2018年
关键词
D O I
10.1109/BIGCOM.2018.00020
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Android permission mechanism is designed to protect the privacy of Android users. An Android application must request permissions when it needs to access sensitive data at runtime. If users do not grant the application requested permissions, the application would not provide functionalities related to these permissions. However, some applications violate this purpose in that they request permissions at initialization. If the user does not grant the requested permissions, these applications would simply exit, refusing to provide any functionalities, including the ones that do not require sensitive data. This behavior of stubbornly requesting permissions damages the right of users in utilizing non-sensitive functionalities. To address this problem, we propose an approach to detect this kind of permission requests. First, we model the key features of stubborn permission requests. Then, we identify the stubborn permission requests by statically analyzing Android applications. We evaluate our approach with real-world market applications and the experimental result shows that our app roach can effectively detect stubborn permission requests in Android applications.
引用
收藏
页码:84 / 89
页数:6
相关论文
共 50 条
  • [1] Overprivileged Permission Detection for Android Applications
    Wu, Sha
    Liu, Jiajia
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [2] Detecting Permission Over-claim of Android Applications with Static and Semantic Analysis Approach
    Tang, Junwei
    Li, Ruixuan
    Han, Hongmu
    Zhang, Heng
    Gu, Xiwu
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 706 - 713
  • [3] Permlyzer: Analyzing Permission Usage in Android Applications
    Xu, Wei
    Zhang, Fangfang
    Zhu, Sencun
    2013 IEEE 24TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE), 2013, : 400 - 410
  • [4] A Permission verification approach for android mobile applications
    Geneiatakis, Dimitris
    Fovino, Igor Nai
    Kounelis, Ioannis
    Stirparo, Paquale
    COMPUTERS & SECURITY, 2015, 49 : 192 - 205
  • [5] You Are (not) Who Your Peers Are: Identification of Potentially Excessive Permission Requests in Android Apps
    Mallojula, Prashanthi
    Ahmad, Javaria
    Li, Fengjun
    Luo, Bo
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 114 - 121
  • [6] Multilevel Permission Extraction in Android Applications for Malware Detection
    Wang, Zhen
    Li, Kai
    Hu, Yan
    Fukuda, Akira
    Kong, Weiqiang
    PROCEEDING OF THE 2019 INTERNATIONAL CONFERENCE ON COMPUTER, INFORMATION AND TELECOMMUNICATION SYSTEMS (IEEE CITS 2019), 2019, : 221 - 225
  • [7] Component-based permission management of Android applications
    Fu, Jiaojiao
    Zhou, Yangfan
    Wang, Xin
    SOFTWARE-PRACTICE & EXPERIENCE, 2019, 49 (09): : 1402 - 1418
  • [8] PUREDroid: Permission Usage and Risk Estimation for Android Applications
    Alshehri, Ali
    Marcinek, Pawel
    Alzahrani, Abdulrahman
    Alshahrani, Hani
    Fu, Huirong
    PROCEEDINGS OF 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEM AND DATA MINING (ICISDM 2019), 2019, : 179 - 184
  • [9] Detecting Wearable App Permission Mismatches: A Case Study on Android Wear
    Mujahid, Suhaib
    ESEC/FSE 2017: PROCEEDINGS OF THE 2017 11TH JOINT MEETING ON FOUNDATIONS OF SOFTWARE ENGINEERING, 2017, : 1065 - 1067
  • [10] Perman: Fine-grained Permission Management for Android Applications
    Fu, Jiaojiao
    Zhou, Yangfan
    Liu, Huan
    Kang, Yu
    Wang, Xin
    2017 IEEE 28TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE), 2017, : 250 - 259