M-Perm: A Lightweight Detector for Android Permission Gaps.

MOBILESoft@ICSE(2017)

引用 18|浏览17
暂无评分
摘要
Android apps operate under a permissions-based system where access to specific APIs are restricted through the use of permissions. Unfortunately, there is no built-in verification system to ensure that apps do not request too many or too few permissions, which could lead to serious quality and/or privacy concerns. Apps requesting too many permissions create unnecessary vulnerabilities, leaving the potential for abuse by SDKs within the app or other malicious apps installed on the device. In order to assist with the discovery of misused permissions, we created a new detection tool, M-Perm, which combines static and dynamic analysis in a computationally efficient manner compared to existing tools. M-Perm also identifies permission usage in apps including requested normal, dangerous, and 3rd party permissions. The tool, complete usage instructions, and screencast are available online: http://www.m-perm.com
更多
查看译文
关键词
apps permission usage,dynamic analysis,static analysis,detection tool,misused permission discovery,malicious apps,SDK abuse,privacy concerns,built-in verification system,API access,permissions-based system where,Android apps,Android permission gaps,lightweight detector,M-Perm
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要