Detecting over-claim permissions and recognising dangerous permission in Android apps

被引:0
|
作者
Shah, Monika [1 ]
机构
[1] Nirma Univ Ahmedabad, Inst Technol, Dept Comp Sci & Engn, Ahmadabad, Gujarat, India
关键词
app upgrade; Android permission model; over-claim permission; dangerous permission; information security;
D O I
10.1504/IJICS.2022.121298
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Android's security is one of the hot research topics in the current days. This is mainly due to the leakage of user's privacy information from third-party apps on mobile. Even after the permission model defined by Android we all are witnessing leakage of our critical information. This is mainly due to: 1) the permission model is proportionally coarse granular; 2) insufficient knowledge of user makes him approve over-claim permission mistakenly. Henceforth this paper focuses on recognising dangerous over-claim permission. This starts with describing the permission model, over-claim permission, and some of the dangerous over-claim permission. This paper specifically proposes an algorithm to detect the signature of dangerous permission incorporated during the upgrading version of third-party software.
引用
收藏
页码:204 / 218
页数:15
相关论文
共 5 条
  • [1] Detecting Permission Over-claim of Android Applications with Static and Semantic Analysis Approach
    Tang, Junwei
    Li, Ruixuan
    Han, Hongmu
    Zhang, Heng
    Gu, Xiwu
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 706 - 713
  • [2] How Dangerous Permissions are Described in Android Apps' Privacy Policies?
    Baalous, Rawan
    Poet, Ronald
    11TH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS (SIN 2018), 2018,
  • [3] Utilizing Sentence Embedding for Dangerous Permissions Detection in Android Apps' Privacy Policies
    Baalous, Rawan
    Poet, Ronald
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2021, 15 (01) : 173 - 189
  • [4] Detecting Permission Crashes of Android Apps using Crawling and Revoke Operation Injections
    Liu, Chien-Hung
    Liu, Chen-Tzung
    Li, Hsiu-Hao
    2021 28TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE WORKSHOPS (APSECW 2021), 2021, : 47 - 51
  • [5] Detecting and Defending against Inter-App Permission Leaks in Android Apps
    He, Yi
    Li, Qi
    2016 IEEE 35TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2016,