信息网络安全 ›› 2015, Vol. 15 ›› Issue (9): 89-92.doi: 10.3969/j.issn.1671-1122.2015.09.021

• 入选论文 • 上一篇    下一篇

一个应对Android应用抬权攻击的系统框架设计

邵旭东1(), 刘洋2   

  1. 1. 公安部第三研究所,上海201204
    2. 上海辰锐信息科技公司, 上海201204
  • 收稿日期:2015-07-15 出版日期:2015-09-01 发布日期:2015-11-13
  • 作者简介:

    作者简介: 邵旭东(1976-),男,浙江,助理研究员,硕士,主要研究方向:信息安全;刘洋(1973-),男,江西,硕士,主要研究方向:嵌入式系统和信息安全。

A Framework Design for Preventing Android from Apps Privilege-Escalation Attacks

Xu-dong SHAO1(), Yang LIU2   

  1. 1.The Third Research Institute of Ministry of Public Security, Shanghai 201204, China
    2.Shanghai Chenrui Information Technology Corporation, Shanghai 201204, China
  • Received:2015-07-15 Online:2015-09-01 Published:2015-11-13

摘要:

最近的研究纷纷指出Android系统易遭受应用级的抬权攻击。但这些研究大都注重该类攻击中的混淆代理人攻击,而对其中的联合攻击缺乏考虑。文章分析了Android安全框架的实现设计与实现,并研究了联合攻击的防御方法,针对Android恶意程序,设计并实现一个系统级框架,以应对潜在的联合攻击,弥补Android系统易被抬权的漏洞。

关键词: Android, 抬权攻击, 联合攻击, 混淆代理人攻击

Abstract:

Android has been pointed in recent researches it is easy suffered from app’s privilege-escalation attacks. But most of the researches focus on confused deputy attacks, and they are lack of consideration about collusion attacks. In this paper, Android’s security framework is analyzed, and the defense methods for the collusion attacks are studied. Also, a new system level security framework for Android be designed and implemented, in order to taming the potential collusion attacks exploiting its vulnerabilities.

Key words: Android, privilege-escalation attack, collusion attack, confused deputy attack

中图分类号: