• DocumentCode
    660602
  • Title

    Flow Permissions for Android

  • Author

    Holavanalli, Shashank ; Manuel, Don ; Nanjundaswamy, Vishwas ; Rosenberg, Brian ; Feng Shen ; Ko, Steven Y. ; Ziarek, Lukasz

  • Author_Institution
    SUNY - Univ. at Buffalo, Buffalo, NY, USA
  • fYear
    2013
  • fDate
    11-15 Nov. 2013
  • Firstpage
    652
  • Lastpage
    657
  • Abstract
    This paper proposes Flow Permissions, an extension to the Android permission mechanism. Unlike the existing permission mechanism our permission mechanism contains semantic information based on information flows. Flow Permissions allow users to examine and grant explicit information flows within an application (e.g., a permission for reading the phone number and sending it over the network) as well as implicit information flows across multiple applications (e.g., a permission for reading the phone number and sending it to another application already installed on the user´s phone). Our goal with Flow Permissions is to provide visibility into the holistic behavior of the applications installed on a user´s phone. Our evaluation compares our approach to dynamic flow tracking techniques; our results with 600 popular applications and 1,200 malicious applications show that our approach is practical and effective in deriving Flow Permissions statically.
  • Keywords
    Android (operating system); Android permission mechanism; flow permissions; information flows; semantic information; Androids; Browsers; Humanoid robots; Java; MySpace; Seals; Smart phones;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Automated Software Engineering (ASE), 2013 IEEE/ACM 28th International Conference on
  • Conference_Location
    Silicon Valley, CA
  • Type

    conf

  • DOI
    10.1109/ASE.2013.6693128
  • Filename
    6693128