论文标题

采取正式的方法来检测Android权限系统中的漏洞

Towards a Formal Approach for Detection of Vulnerabilities in the Android Permissions System

论文作者

Sayyadabdi, Amirhosein, Ladani, Behrouz Tork, Zamani, Bahman

论文摘要

Android是一种使用基于许可的访问控制模型的广泛使用的操作系统。 Android权限系统(APS)负责调解应用程序资源请求。 APS是Android安全机制的关键组成部分;因此,APS设计的失败可能会导致漏洞,这些漏洞通过恶意应用程序授予未经授权访问资源的漏洞。在本文中,我们提出了一种正式的方法,用于建模和验证AP的安全性。我们通过展示了对Android自定义权限中发现的众所周知漏洞的检测来证明所提出方法的可用性。

Android is a widely used operating system that employs a permission-based access control model. The Android Permissions System (APS) is responsible for mediating application resource requests. APS is a critical component of the Android security mechanism; hence, a failure in the design of APS can potentially lead to vulnerabilities that grant unauthorized access to resources by malicious applications. In this paper, we present a formal approach for modeling and verifying the security properties of APS. We demonstrate the usability of the proposed approach by showcasing the detection of a well-known vulnerability found in Android's custom permissions.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源