Overprivileged Permission Detection for Android Applications

Sha Wu, Jiajia Liu

科研成果: 书/报告/会议事项章节会议稿件同行评审

18 引用 (Scopus)

摘要

Android applications (Apps) have penetrated almost every aspect of our lives, bring users great convenience as well as security concerns. Even though Android system adopts permission mechanism to restrict Apps from accessing important resources of a smartphone, such as telephony, camera and GPS location, users face still significant risk of privacy leakage due to the overprivileged permissions. The overprivileged permission means the extra permission declared by the App but has nothing to do with its function. Unfortunately, there doesn't exist any tool for ordinary users to detect the overprivileged permission of an App, hence most users grant any permission declared by the App, intensifying the risk of private information leakage. Although some previous studies tried to solve the problem of permission overprivilege, their methods are not applicable nowadays because of the progress of App protection technology and the update of Android system. Towards this end, we develop a user-friendly tool based on frequent item set mining for the detection of overprivileged permissions of Android Apps, which is named Droidtector. Droidtector can operate in online or offline mode and users can choose any mode according to their situation. Finally, we run Droidtector on 1000 Apps crawled from Google Play and find that 479 of them are overprivileged, accounting for about 48% of all the sample Apps.

源语言英语
主期刊名2019 IEEE International Conference on Communications, ICC 2019 - Proceedings
出版商Institute of Electrical and Electronics Engineers Inc.
ISBN(电子版)9781538680889
DOI
出版状态已出版 - 5月 2019
已对外发布
活动2019 IEEE International Conference on Communications, ICC 2019 - Shanghai, 中国
期限: 20 5月 201924 5月 2019

出版系列

姓名IEEE International Conference on Communications
2019-May
ISSN(印刷版)1550-3607

会议

会议2019 IEEE International Conference on Communications, ICC 2019
国家/地区中国
Shanghai
时期20/05/1924/05/19

指纹

探究 'Overprivileged Permission Detection for Android Applications' 的科研主题。它们共同构成独一无二的指纹。

引用此