PrivDroid: Android Security Code Smells Tool for Privilege Escalation Prevention.

2023 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC/PiCom/CBDCom/CyberSciTech)(2023)

引用 0|浏览0
暂无评分
摘要
Privilege Escalation (PE) attacks are common security issues in Android ecosystem. They typically involve the exploitation of vulnerabilities to gain unauthorized access to sensitive data. Preventing their related vulnerabilities is complex and hard to be understood and mitigated by developers. In a previous research, we performed an empirical study to investigate the effectiveness of existing IDE plugins in detecting known Android related vulnerabilities. We found that most of PE vulnerabilities are not covered by these IDE plugins. In order to assist developers to evade these issues, we present in this paper PrivDroid, an up to date and available IDE plugin for secure Android development. The tool combines static analysis techniques on the Android project source files to identify security code smells related to PE. Finally, PrivDroid is tested against more than 200 real Android applications and demonstrates that it gives additional capabilities to prevent Privilege Escalation related vulnerabilities.
更多
查看译文
关键词
Android,Secure Coding,Privilege Escalation,Code Smells
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要