DocumentCode :
660602
Title :
Flow Permissions for Android
Author :
Holavanalli, Shashank ; Manuel, Don ; Nanjundaswamy, Vishwas ; Rosenberg, Brian ; Feng Shen ; Ko, Steven Y. ; Ziarek, Lukasz
Author_Institution :
SUNY - Univ. at Buffalo, Buffalo, NY, USA
fYear :
2013
fDate :
11-15 Nov. 2013
Firstpage :
652
Lastpage :
657
Abstract :
This paper proposes Flow Permissions, an extension to the Android permission mechanism. Unlike the existing permission mechanism our permission mechanism contains semantic information based on information flows. Flow Permissions allow users to examine and grant explicit information flows within an application (e.g., a permission for reading the phone number and sending it over the network) as well as implicit information flows across multiple applications (e.g., a permission for reading the phone number and sending it to another application already installed on the user´s phone). Our goal with Flow Permissions is to provide visibility into the holistic behavior of the applications installed on a user´s phone. Our evaluation compares our approach to dynamic flow tracking techniques; our results with 600 popular applications and 1,200 malicious applications show that our approach is practical and effective in deriving Flow Permissions statically.
Keywords :
Android (operating system); Android permission mechanism; flow permissions; information flows; semantic information; Androids; Browsers; Humanoid robots; Java; MySpace; Seals; Smart phones;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Automated Software Engineering (ASE), 2013 IEEE/ACM 28th International Conference on
Conference_Location :
Silicon Valley, CA
Type :
conf
DOI :
10.1109/ASE.2013.6693128
Filename :
6693128
Link To Document :
بازگشت