Bitte benutzen Sie diese Referenz, um auf diese Ressource zu verweisen: doi:10.22028/D291-25206
Titel: AppGuard - real-time policy enforcement for third-party applications
VerfasserIn: Backes, Michael
Gerling, Sebastian
Hammer, Christian
Maffei, Matteo
von Styp-Rekowsky, Philipp
Sprache: Englisch
Erscheinungsjahr: 2012
Kontrollierte Schlagwörter: Echtzeitsystem
Freie Schlagwörter: operating system
DDC-Sachgruppe: 004 Informatik
Dokumenttyp: Forschungsbericht (Report zu Forschungsprojekten)
Abstract: Android has become the most popular operating system for mobile devices, which makes it a prominent target for malicious software. The security concept of Android is based on app isolation and access control for critical system resources. However, users can only review and accept permission requests at install time, or else they cannot install an app at all. Android neither supports permission revocation after the installation of an app, nor dynamic permission assignment. Additionally, the current permission system is too coarse for many tasks and cannot easily be refined. We present an inline reference monitor system that overcomes these deficiencies. It extends Android’s permission system to impede overly curious behaviors; it supports complex policies, and mitigates vulnerabilities of third-party apps and the OS. It is the first solution that provides a practical extension of the current Android permission system as it can be deployed to all Android devices without modification of the firmware or root access to the smartphone. Our experimental analysis shows that we can remove permissions for overly curious apps as well as defend against several recent real-world attacks on Android phones with very little space and runtime overhead. AppGuard is available from the Google Play market.
Link zu diesem Datensatz: urn:nbn:de:bsz:291-scidok-49028
hdl:20.500.11880/25262
http://dx.doi.org/10.22028/D291-25206
Schriftenreihe: Technischer Bericht / A / Fachbereich Informatik, Universität des Saarlandes
Band: 2012/02
Datum des Eintrags: 16-Jul-2012
Fakultät: SE - Sonstige Einrichtungen
Fachrichtung: SE - Max-Planck-Institut für Informatik
MI - Informatik
Sammlung:SciDok - Der Wissenschaftsserver der Universität des Saarlandes

Dateien zu diesem Datensatz:
Datei Beschreibung GrößeFormat 
android_irm.pdf1,25 MBAdobe PDFÖffnen/Anzeigen


Alle Ressourcen in diesem Repository sind urheberrechtlich geschützt.