维普中文期刊产品整合服务

Communication-Based Attacks Detection in Android Applications

查看全文 作  者:Chuan [1]Ma;Tao [2]Wang;Limin [1]Shen;Dongkui [1]Liang;Shuping [3]Chen;Dianlong [1]You 高影响力作者 机构地区:[1]School of In formation Science and Engineering, Yanshan University, the Key Laboratory for Computer Virtual Technology and System Integration of Hebei Province, Qinhuangdao 066004, China;[2]School of Business Ad mi nisliatiom Hebei Normal University of Science and Technology. Qinhuangdao 066004, China;[3]Library of Yanshan University. Yanshan University, Qinhuangdao 066004, China高影响力机构 出  处:《Tsinghua Science and Technology》索引2019年第24卷第5期,共19页高影响力期刊 基  金:supported by the Hebei Provincial Natural Science Foundation(Nos.F2016203290 and F2017203307);the National Natural Science Foundation of China(No.61772450);the Doctoral Foundation of Yanshan University(Nos.BL18011 and B906);the Hebei Normal University of Science and Technology Scientific Research Foundation(No.2018YB019);the China Postdoctoral Science Foundation(No.2018M631764);the Hebei Province Science and Technology Planning Project(No.17210701D) 摘  要:The Android operating system provides a rich Inter-Component Communication(ICC) method that brings enormous convenience. However, the Android ICC also increases security risks. To address this problem, a formal method is proposed to model and detect inter-component communication behavior in Android applications. Firstly,we generate data flow graphs and data facts for each component through component-level data flow analysis.Secondly, our approach treats ICC just like method calls. After analyzing the fields and data dependencies of the intent, we identify the ICC caller and callee, track the data flow between them, and construct the ICC model. Thirdly,the behavior model of Android applications is constructed by a formal mapping method for component data flow graph based on Pi calculus. The runtime sensitive path trigger detection algorithm is then given. Communicationbased attacks are detected by analyzing intent abnormity. Finally, we analyze the modeling and detection efficiency,and compare it with relevant methods. Analysis of 57 real-world applications partly verifies the effectiveness of the proposed method. 关 键 词:ANDROID inter-component COMMUNICATION intents COMPONENT HIJACKING attack DETECTION
相关文献

参考文献(28)

引证文献(2)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费