Contribution à des ouvrages collectifs (Parties d’ouvrages)
Automatically Securing Permission-Based Software by Reducing the Attack Surface: An Application to Android
BARTEL, Alexandre; KLEIN, Jacques; Monperrus, Martin et al.
2011In Automatically Securing Permission-Based Software by Reducing the Attack Surface: An Application to Android (Tech Report)
 

Documents


Texte intégral
AttackSurfaceReduction-tr.pdf
Postprint Auteur (445.09 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
call-graph; android; security; soot; java; static analysis
Résumé :
[en] Android based devices are becoming widespread. As a result and since those devices contain personal and confidential data, the security model of the android software stack has been analyzed extensively. One key feature of the security model is that applications must declare a list of permissions they are using to access resources. Using static analysis, we first extracted a table from the Android API which maps methods to permissions. Then, we use this mapping within a tool we developed to check that applications effectively need all the permissions they declare. Using our tool on a set of android applications, we found out that a non negligible part of the applications do not use all the permissions they declare. Consequently, the attack surface of such applications can be reduced by removing the non-needed permissions.
Disciplines :
Sciences informatiques
Identifiants :
UNILU:UL-CHAPTER-2011-185
Auteur, co-auteur :
BARTEL, Alexandre ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
KLEIN, Jacques  ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Monperrus, Martin;  University of Lille, France
LE TRAON, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Langue du document :
Anglais
Titre :
Automatically Securing Permission-Based Software by Reducing the Attack Surface: An Application to Android
Date de publication/diffusion :
2011
Titre de l'ouvrage principal :
Automatically Securing Permission-Based Software by Reducing the Attack Surface: An Application to Android (Tech Report)
Maison d'édition :
Tech Report
ISBN/EAN :
9782879711072
Pagination :
1-11
Commentaire :
Tech Report
Disponible sur ORBilu :
depuis le 16 juillet 2013

Statistiques


Nombre de vues
264 (dont 4 Unilu)
Nombre de téléchargements
224 (dont 0 Unilu)

Bibliographie


Publications similaires



Contacter ORBilu