Overprivileged Permission Detection for Android Applications

Sha Wu, Jiajia Liu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

18 Scopus citations

Abstract

Android applications (Apps) have penetrated almost every aspect of our lives, bring users great convenience as well as security concerns. Even though Android system adopts permission mechanism to restrict Apps from accessing important resources of a smartphone, such as telephony, camera and GPS location, users face still significant risk of privacy leakage due to the overprivileged permissions. The overprivileged permission means the extra permission declared by the App but has nothing to do with its function. Unfortunately, there doesn't exist any tool for ordinary users to detect the overprivileged permission of an App, hence most users grant any permission declared by the App, intensifying the risk of private information leakage. Although some previous studies tried to solve the problem of permission overprivilege, their methods are not applicable nowadays because of the progress of App protection technology and the update of Android system. Towards this end, we develop a user-friendly tool based on frequent item set mining for the detection of overprivileged permissions of Android Apps, which is named Droidtector. Droidtector can operate in online or offline mode and users can choose any mode according to their situation. Finally, we run Droidtector on 1000 Apps crawled from Google Play and find that 479 of them are overprivileged, accounting for about 48% of all the sample Apps.

Original languageEnglish
Title of host publication2019 IEEE International Conference on Communications, ICC 2019 - Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781538680889
DOIs
StatePublished - May 2019
Externally publishedYes
Event2019 IEEE International Conference on Communications, ICC 2019 - Shanghai, China
Duration: 20 May 201924 May 2019

Publication series

NameIEEE International Conference on Communications
Volume2019-May
ISSN (Print)1550-3607

Conference

Conference2019 IEEE International Conference on Communications, ICC 2019
Country/TerritoryChina
CityShanghai
Period20/05/1924/05/19

Keywords

  • Android application
  • detection tool
  • frequent item set mining
  • overprivileged permission

Fingerprint

Dive into the research topics of 'Overprivileged Permission Detection for Android Applications'. Together they form a unique fingerprint.

Cite this