An Android runtime security policy enforcement framework

被引:15
作者
Banuri, Hammad [1 ]
Alam, Masoom [1 ]
Khan, Shahryar [1 ]
Manzoor, Jawad [1 ]
Ali, Bahar [1 ]
Khan, Yasar [1 ]
Yaseen, Mohsin [1 ]
Tahir, Mir Nauman [1 ]
Ali, Tamleek [1 ]
Alam, Quratulain [1 ]
Zhang, Xinwen [2 ]
机构
[1] Inst Management Sci, Secur Engn Res Grp SERG, Peshawar, Pakistan
[2] Huawei Res Ctr, Santa Clara, CA USA
关键词
Android security; Permission labels; Smart phone malwares;
D O I
10.1007/s00779-011-0437-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today, smart phone's malwares are deceptive enough to spoof itself as a legal mobile application. The front-end service of Trojans is attractive enough to deceive mobile users. Mobile users download similar malwares without knowing their illegitimate background threat. Unlike other vendors, Android is an open-source mobile operating system, and hence, it lacks a dedicated team to analyze the application code and decide its trustworthiness. We propose an augmented framework for Android that monitors the dynamic behavior of application during its execution. Our proposed architecture called Security Enhanced Android Framework (seaf) validates the behavior of an application through its permissions exercising patterns. Based on the exercised permissions' combination, the mobile user is intimated about the dangerous behavior of an application. We have implemented the proposed framework within Android software stack and ported it to device. Our initial investigation shows that our solution is practical enough to be used in the consumer market.
引用
收藏
页码:631 / 641
页数:11
相关论文
共 16 条
[1]  
[Anonymous], SERG REF
[2]  
[Anonymous], ANDROID REFERENCE MA
[3]  
[Anonymous], 2007, APPLE APP STORE APPR
[4]  
[Anonymous], ANDROID REFERENCE CL
[5]  
[Anonymous], ANDROID APPL SMS REP
[6]  
[Anonymous], NASTR00942008 PENNS
[7]  
[Anonymous], ANDROID REFERENCE AN
[8]  
[Anonymous], ANDROID REFERENCE SE
[9]  
CHAUDHURI A., 2009, P ACM SIGPLAN 4 WORK, P1, DOI [DOI 10.1145/1554339.1554341, 10.1145/1667209.1667211]
[10]  
ENCK W, 2009, P 16 ACM C COMP COMM, P235