Assisting Developers in Preventing Permissions Related Security Issues in Android Applications

被引:1
|
作者
Tebib, Mohammed El Amin [1 ]
Andre, Pascal [2 ]
Aktouf, Oum-El-Kheir [1 ]
Graa, Mariem [3 ]
机构
[1] Univ Grenoble Alpes, Grenoble INP, LCIS, Valence, France
[2] Univ Nantes, LS2N, CNRS, UMR 6004, Nantes, France
[3] IMT ATLANTIQUE, Nantes, France
来源
关键词
Android; Development; Security; Privacy; Permissions; IDE; MDRE;
D O I
10.1007/978-3-030-86507-8_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Permissions related attacks are a widespread security issue in Android environment. Permissions misuse enables attackers to steal the application rights and perform malicious actions. While most of the existing solutions are advocated from end-users perspective, we take in this paper the developers perspective because security should be a software design concern. We propose a formal specification covering the permissions use by the current developers of Android applications, who are almost a third party developers. We underline a set of security properties. Then, we formally verify them by applying a Model Driven Reverse Engineering approach that enables abstraction and property verification. We implement the analysis approach as an IDE plug-in called PermDroid. Finally, we show the applicability of our approach through a case study.
引用
下载
收藏
页码:132 / 143
页数:12
相关论文
共 50 条
  • [31] Enhancing Trustability of Android Applications via User-Centric Flexible Permissions
    Scoccia, Gian Luca
    Malavolta, Ivano
    Autili, Marco
    Di Salle, Amleto
    Inverardi, Paola
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2021, 47 (10) : 2032 - 2051
  • [32] An Insight into the Security Issues and Their Solutions for Android Phones
    Khandelwal, Ankita
    Mohapatra, A. K.
    2015 2ND INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT (INDIACOM), 2015, : 106 - 109
  • [33] On the Evolution of Security Issues in Android App Versions
    Kalysch, Anatoli
    Schilling, Joschua
    Mueller, Tilo
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2020, 2020, 12418 : 523 - 541
  • [34] Permission based Android security: Issues and countermeasures
    Fang, Zheran
    Han, Weili
    Li, Yingjiu
    COMPUTERS & SECURITY, 2014, 43 : 205 - 218
  • [35] DroidProtector: Preventing Capability Leak of Android Applications
    Sun, Jiyuan
    Ye, Shaozhen
    Liu, Jianwei
    Shang, Tao
    Lei, Qi
    2017 INTERNATIONAL CONFERENCE ON GREEN INFORMATICS (ICGI), 2017, : 163 - 168
  • [36] A Study on Security and Privacy related Issues in Blockchain Based Applications
    Shah, Rujuta
    Sridaran, R.
    PROCEEDINGS OF THE 2019 6TH INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT (INDIACOM), 2019, : 1240 - 1244
  • [37] Android mobile security by detecting and classification of malware based on permissions using machine learning algorithms
    Varma, Ravi Kiran P.
    Raj, Kotari Prudvi
    Raju, K. V. Subba
    2017 INTERNATIONAL CONFERENCE ON I-SMAC (IOT IN SOCIAL, MOBILE, ANALYTICS AND CLOUD) (I-SMAC), 2017, : 294 - 299
  • [38] The Research on Security Reinforcement of Android Applications
    Feng Xiaorong
    Lin Jun
    Jia Shizhun
    PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON MECHATRONICS, MATERIALS, CHEMISTRY AND COMPUTER ENGINEERING 2015 (ICMMCCE 2015), 2015, 39 : 95 - 101
  • [39] Network Security Challenges in Android Applications
    Buhov, Damjan
    Huber, Markus
    Merzdovnik, Georg
    Weippl, Edgar
    Dimitrova, Vesna
    PROCEEDINGS 10TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY ARES 2015, 2015, : 327 - 332
  • [40] Survey regarding the Way Students Perceive Security Permissions of Mobile Applications
    Lorint, Roxana
    Marcu, Marius
    IEEE 13TH INTERNATIONAL SYMPOSIUM ON APPLIED COMPUTATIONAL INTELLIGENCE AND INFORMATICS (SACI 2019), 2019, : 287 - 290