信息网络安全 ›› 2016, Vol. 16 ›› Issue (2): 15-21.doi: 10.3969/j.issn.1671-1122.2016.02.003

• • 上一篇    下一篇

一种安卓平台下提权攻击检测系统的设计与实现

张涛1, 裴蓓2(), 文伟平3, 陈钟1   

  1. 1.北京大学信息科学技术学院,北京100871
    2.信息网络安全公安部重点实验室,上海201204
    3.北京大学软件与微电子学院,北京 102600
  • 收稿日期:2015-12-27 出版日期:2016-02-10 发布日期:2020-05-13
  • 作者简介:

    作者简介: 张涛(1987—),男,江西,博士研究生,主要研究方向为系统与网络安全;裴蓓(1983—),女,安徽,研究实习员,硕士研究生,主要研究方向为信息网络安全认证和项目管理;文伟平(1976—),男,湖南,副教授,博士,主要研究方向为网络攻击与防范、恶意代码研究、信息系统逆向工程等;陈钟(1963—),男,江苏,教授,博士,主要研究方向为系统与网络安全、密码学。

  • 基金资助:
    国家自然科学基金[ 61170282];信息网络安全公安部重点实验室资金[C14604]

Design and Implementation of Privilege Escalation Attack Detecting System Based on Android Platform

Tao ZHANG1, Bei PEI2(), Weiping WEN3, Zhong CHEN1   

  1. 1. School of Electronics Engineering & Computer Sciences, Peking University, Beijing 100871,China
    2. Key Lab of Information Network Security of Ministry of Public Security, Shanghai 201204,China
    3. School of Software and Microelectronics, Peking University, Beijing 102600, China
  • Received:2015-12-27 Online:2016-02-10 Published:2020-05-13

摘要:

随着安卓系统的盛行,其安全性问题也逐渐成为人们关注的焦点。在安卓系统中进行敏感操作必须向系统申请相应的权限。虽然安卓系统中已经设计了与权限控制相关的系统模块,但是攻击者仍然可以借助系统漏洞或第三方程序漏洞进行提权攻击,进而非法使用一些超越其申请权限的功能。此种攻击不但对系统安全威胁较大,还具有一定的隐蔽性。文章通过对以往研究进行分析和创新,提出了一种新型的基于控制流检测和安卓敏感权限词典匹配的轻量级提权攻击检测方法,并在此基础上完成了自动化程度高、检测效率高的检测软件的设计与实现。

关键词: 提权攻击, 检测, 安卓, 控制流, 权限字典

Abstract:

Along with the rapid development of Android mobile operation system, its security issue has taken attentions. In the Android, it is necessary to apply the authorities to the system for sensitive operations. Although some system modules related to authority control have been designed in the Android, the attackers still can use the system vulnerabilities or third party program vulnerabilities to carry out the privilege escalation attack, and then illegally use some functions beyond their application permissions. This kind of attack is not only a great threat to the security of the system, but also has the feature of concealment. Based on the analysis and innovation on the past research, this paper proposes a new light weight method for detecting the privilege escalation attack, which uses the control flow detection and Android sensitive authority dictionary matching. In addition, detection software with high degree of automation and high detection efficiency is designed and implemented on the basis of privilege escalation attack detecting method.

Key words: privilege escalation attack, detection, Android, control flow, authority dictionary

中图分类号: