• DocumentCode
    245601
  • Title

    ASPG: Generating Android Semantic Permissions

  • Author

    Jiayu Wang ; Qigeng Chen

  • Author_Institution
    Dept. of Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
  • fYear
    2014
  • fDate
    19-21 Dec. 2014
  • Firstpage
    591
  • Lastpage
    598
  • Abstract
    Android system has been widely utilized in smartphones, but it also has many security threats. Android uses the permission system to notice the user during installation about what permissions it will receive. However, according to related research, most users have poor understanding of permissions, and will accept the prompt directly. Over privileged applications will expose users to unnecessary permission warnings and increase the impact of a bug or vulnerability. In order to reduce user´s trouble and avoid application over privilege, we focus on permissions for a given application and examine whether the application description provide any indication for why the application needs a permission. We propose an android semantic permission generator (ASPG) to understand what permissions an application needs from user´s perspective. Our ASPG can get the semantic permissions based on the application description. Besides, ASPG will further tailor the semantically unrelated permissions. We analyze ten popular applications using the ASPG, finding that they all contain semantically unrelated permissions. After tailoring the semantically unrelated permissions, most of applications can run normally. Experimental results show ASPG is feasible. In addition, we provide a specification to support our ASPG better when an application runs abnormally.
  • Keywords
    Android (operating system); authorisation; smart phones; ASPG; Android semantic permission generator; Android system; application overprivilege; security threats; semantically unrelated permissions; smartphones; unnecessary permission warnings; Androids; Generators; Humanoid robots; Operating systems; Security; Semantics; Smart phones; android; overprivilege; permission; semantic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Science and Engineering (CSE), 2014 IEEE 17th International Conference on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-1-4799-7980-6
  • Type

    conf

  • DOI
    10.1109/CSE.2014.132
  • Filename
    7023642