首页> 外文会议>Proceedings of the 2012 Third World Congress on Software Engineering. >LeakMiner: Detect Information Leakage on Android with Static Taint Analysis
【24h】

LeakMiner: Detect Information Leakage on Android with Static Taint Analysis

机译:LeakMiner:使用静态污点分析检测Android上的信息泄漏

获取原文
获取原文并翻译 | 示例

摘要

With the growing popularity of Android platform, Android application market becomes a major distribution center where Android users download apps. Unlike most of the PC apps, Android apps manipulates personal information such as contract and SMS messages, and leakage of such information may cause great loss to the Android users. Thus, detecting information leakage on Android is in urgent need. However, till now, there is still no complete vetting process applied to Android markets. State-of-the-art approaches for detecting Android information leakage apply dynamic analysis on user site, thus they introduce large runtime overhead to the Android apps. This paper proposes a new approach called Leak Miner, which detects leakage of sensitive information on Android with static taint analysis. Unlike dynamic approaches, Leak Miner analyzes Android apps on market site. Thus, it does not introduce runtime overhead to normal execution of target apps. Besides, Leak Miner can detect information leakage before apps are distributed to users, so malicious apps can be removed from market before users download them. Our evaluation result shows that Leak Miner can detect 145 true information leakages inside a 1750 app set.
机译:随着Android平台的日益普及,Android应用程序市场已成为Android用户下载应用程序的主要发行中心。与大多数PC应用程序不同,Android应用程序会处理诸如合同和SMS消息之类的个人信息,并且此类信息的泄漏可能会给Android用户带来巨大损失。因此,迫切需要在Android上检测信息泄漏。但是,到目前为止,还没有将完整的审核过程应用于Android市场。用于检测Android信息泄漏的最新方法在用户站点上进行了动态分析,因此将大量的运行时开销引入了Android应用程序。本文提出了一种名为Leak Miner的新方法,该方法可通过静态污点分析检测Android上敏感信息的泄漏。与动态方法不同,Leak Miner会分析市场站点上的Android应用程序。因此,它不会给目标应用程序的正常执行带来运行时开销。此外,Leak Miner可以在将应用分发给用户之前检测到信息泄漏,因此可以在用户下载恶意应用之前将其从市场中删除。我们的评估结果表明,Leak Miner可以检测到1750个应用程序集中的145个真实信息泄漏。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号