Spartan Jester: End-to-End Information Flow Control for Hybrid Android Applications

2017 IEEE Security and Privacy Workshops (SPW)(2017)

引用 6|浏览20
暂无评分
摘要
Web-based applications are attractive due to their portability. To leverage that, many mobile applications are hybrid, incorporating a web component that implements most of their functionality. While solutions for enforcing security exist for both mobile and web applications, enforcing and reasoning about the security of their combinations is difficult. We argue for a combination of static and dynamic analysis for assurance of end-to-end confidentiality in hybrid apps. We show how information flows in hybrid Android applications can be secured through use of SPARTA, a static analyzer for Android/Java, and JEST, a dynamic monitor for JavaScript, connected by a compatibility layer that translates policies and value representations. This paper reports on our preliminary investigation using a case study.
更多
查看译文
关键词
spartan Jester,end-to-end information flow control,hybrid Android applications,mobile applications,web component,static analysis,dynamic analysis,end-to-end confidentiality,hybrid apps,Android,security enforcement,Java
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要