AppGuard — Real-time policy en- forcement for third-party applications

نویسندگان

  • Michael Backes
  • Sebastian Gerling
  • Christian Hammer
  • Matteo Maffei
  • Philipp von Styp-Rekowsky
چکیده

Android has become the most popular operating system for mobile devices, which makes it a prominent target for malicious software. The security concept of Android is based on app isolation and access control for critical system resources. However, users can only review and accept permission requests at install time, or else they cannot install an app at all. Android neither supports permission revocation after the installation of an app, nor dynamic permission assignment. Additionally, the current permission system is too coarse for many tasks and cannot easily be refined. We present an inline reference monitor system that overcomes these deficiencies. It extends Android’s permission system to impede overly curious behaviors; it supports complex policies, and mitigates vulnerabilities of third-party apps and the OS. It is the first solution that provides a practical extension of the current Android permission system as it can be deployed to all Android devices without modification of the firmware or root access to the smartphone. Our experimental analysis shows that we can remove permissions for overly curious apps as well as defend against several recent real-world attacks on Android phones with very little space and runtime overhead. AppGuard is available from the Google Play market1.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

AppGuard - Fine-Grained Policy Enforcement for Untrusted Android Applications

Android’s success makes it a prominent target for malicious software. However, the user has very limited control over security-relevant operations. This work presents AppGuard, a powerful and flexible security system that overcomes these deficiencies. It enforces user-defined security policies on untrusted Android applications without requiring any changes to a smartphone’s firmware, root acces...

متن کامل

A multilevel file system for high assurance

The designs of applications for multilevel systems cannot merely duplicate those of the untrusted world When applications are built on a high assurance base they will be constrained by the underlying policy en forcement mechanism Consideration must be given to the creation and management of multilevel data struc tures by untrusted subjects Applications should be de signed to rely upon the TCB s...

متن کامل

AppGuard - Enforcing User Requirements on Android Apps

The success of Android phones makes them a prominent target for malicious software, in particular since the Android permission system turned out to be inadequate to protect the user against security and privacy threats. This work presents AppGuard, a powerful and flexible system for the enforcement of user-customizable security policies on untrusted Android applications. AppGuard does not requi...

متن کامل

An artificial intelligence model based on LS-SVM for third-party logistics provider ‎selection

The use of third-party logistics (3PL) providers is regarded as new strategy in logistics management. The relationships by considering 3PL are sometimes more complicated than any classical logistics supplier relationships. These relationships have taken into account as a well-known way to highlight organizations' flexibilities to regard rapidly uncertain market conditions, follow core competenc...

متن کامل

Enteral nutrition reimbursement - the rationale for the policy: the US perspective.

Enteral nutrition (EN) is generally defined by third party payers as tube feeding for patients who cannot take food orally. EN is widely accepted in the United States as an effective, often life-sustaining therapy. Coverage and payment policies for EN differ among payers and settings. These differences often may depend on whether EN is reimbursed as a discrete therapy or subsumed into a larger ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012