DocumentCode :
245601
Title :
ASPG: Generating Android Semantic Permissions
Author :
Jiayu Wang ; Qigeng Chen
Author_Institution :
Dept. of Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
fYear :
2014
fDate :
19-21 Dec. 2014
Firstpage :
591
Lastpage :
598
Abstract :
Android system has been widely utilized in smartphones, but it also has many security threats. Android uses the permission system to notice the user during installation about what permissions it will receive. However, according to related research, most users have poor understanding of permissions, and will accept the prompt directly. Over privileged applications will expose users to unnecessary permission warnings and increase the impact of a bug or vulnerability. In order to reduce user´s trouble and avoid application over privilege, we focus on permissions for a given application and examine whether the application description provide any indication for why the application needs a permission. We propose an android semantic permission generator (ASPG) to understand what permissions an application needs from user´s perspective. Our ASPG can get the semantic permissions based on the application description. Besides, ASPG will further tailor the semantically unrelated permissions. We analyze ten popular applications using the ASPG, finding that they all contain semantically unrelated permissions. After tailoring the semantically unrelated permissions, most of applications can run normally. Experimental results show ASPG is feasible. In addition, we provide a specification to support our ASPG better when an application runs abnormally.
Keywords :
Android (operating system); authorisation; smart phones; ASPG; Android semantic permission generator; Android system; application overprivilege; security threats; semantically unrelated permissions; smartphones; unnecessary permission warnings; Androids; Generators; Humanoid robots; Operating systems; Security; Semantics; Smart phones; android; overprivilege; permission; semantic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Science and Engineering (CSE), 2014 IEEE 17th International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4799-7980-6
Type :
conf
DOI :
10.1109/CSE.2014.132
Filename :
7023642
Link To Document :
بازگشت