期刊文献+

国内Android应用商城中程序隐私泄露分析 被引量:19

Empirical study of privacy leakage in Android marketplaces in China
原文传递
导出
摘要 Android系统的开放性和Android应用商城缺乏有效的安全核查工具,导致以获取用户隐私信息为目的的程序不断涌现。该文聚焦于国内Android应用商城中程序隐私泄露问题,结合Android系统的权限机制,采用程序静态分析技术获取程序中疑似泄露路径,然后采用动态验证技术进行隐私泄露行为的确认。该文分析和研究了国内7个最具代表性的应用商城的330个热门程序,发现有58%的程序在用户隐私泄露方面存在问题。 Most mobile devices are now based on the Android operating system platform with almost all applications(called apps) downloaded from a few centralized software distribution sites,called marketplaces.However,the lack of effective security vetting mechanisms as well as the Android openness means that the marketplaces may unintentionally be hosting many apps developed by third parties who intend to manipulate and collect user privacy data for a variety of purposes.This paper reports an empirical study of the privacy leakage problem for about 330 of the most popular apps from seven representative Android marketplaces in China.A two-step process was used to minimize false alarms with each app initially examined by a static analysis tool and,if this examination reported suspicious code segments,the app was then tracked dynamically within a controlled run-time environment to identify the actual privacy leakage.The evaluation results show that more than 58% of the apps lead privacy data without user consent.
出处 《清华大学学报(自然科学版)》 EI CAS CSCD 北大核心 2012年第10期1420-1426,共7页 Journal of Tsinghua University(Science and Technology)
基金 教育部-英特尔信息技术专项科研基金资助项目(MOE-INTEL-2012-02) 上海市科学技术委员会科研计划资助项目(11511504404)
关键词 ANDROID 应用商城 隐私泄露 Android marketplace privacy leakage
  • 相关文献

参考文献11

  • 1凤凰网.2012年中国智能手机市场趋势观察研究预测报告[Z/OL].(2012-03-21),http://tech.ifeng.com/digi/special/wpchina/content-3/detail_2012_03/21/13331085_0.shtml.
  • 2网秦.2012年第一季度全球Android手机安全报告[Z/OL].(2012-04-19),http://news.jschina.com.cn/system/2012/04/19/013174893.shtml.
  • 3中国创新网.2012年第一季度全球智能手机调查报告[Z/OL].(2012-05-03),http://www.chinahightech.com/html/737/2012/0504/112400.htm.
  • 4和讯网.2012年第一季度中国智能手机市场研究报告(简版)[Z/OL].(2012-05-02),http://tech.hexun.com/2012-05-02/140974981.html.
  • 5腾讯科技.解析国内Android应用市场竞争出路[Z/OL].(2011-12-01),http://tech.qq.com/a/20111201/000352.htm.
  • 6Google:Android Developers Website.Android and security[Z/OL].(2012-02-21),http://googlemobile.blogspot.com/2012/02/android-and-security.html.
  • 7Adrienne P,Erika C,Steve H,et al.Android permissionsdemystified[C] //Proceedings of the 18th ACM Conferenceon Computer and Communications Security.Chicago,USA:ACM,2011:627-638.
  • 8William E,Peter G,Chun B,et al.TaintDroid:Aninformation-flow tracking system for realtime privacymonitoring on smartphones[C] //Proceedings of the 9thUsenix Symposium on Operating Systems Design andImplementation.Vancouver,Canada:USENIX,2010:1-6.
  • 9Google:Android-Apktool.Project home:Android-apktool[Z/OL].(2012-12-08).http://code.google.com/p/android-apktool.
  • 10Ded.Decompiling Android application[Z/OL].(2011-08-17).http://siis.cse.psu.edu/ded/index.html.

同被引文献183

引证文献19

二级引证文献198

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部