TripleMon: A multi-layer security framework for mediating inter-process communication on Android

نویسندگان

  • Yiming Jing
  • Gail-Joon Ahn
  • Hongxin Hu
  • Haehyun Cho
  • Ziming Zhao
چکیده

As smartphones have become an indispensable part of daily life, mobile users are increasingly relying on them to process personal information with feature-rich applications. This situation requires robust security mechanisms for protecting sensitive applications and data on mobile devices. Android, as one the most popular smartphone operating systems, provides two core security mechanisms, application sandboxing and a permission system. However, recent studies show that these mechanisms are vulnerable to be passed by a variety of attacks. In this paper, we argue for the need of designing and implementing more comprehensive security mechanisms for Android. We realize that mediating Inter-Process Communication (IPC) channels used by Android applications can mitigate prominent attacks effectively and efficiently. Based on this observation, we propose a practical multi-layer security framework called TRIPLEMON to support policy-based mediation on Android IPC. We also discuss and evaluate a proof-of-concept prototype of TRIPLEMON along with the experimental results derived from real malware samples and synthetic attacks.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards Multi - layered Security for Mediating Inter - Process Communication on Android

1. A Cloud-based Resource and Service Sharing Platform for Computer and Network Security Education Dijiang Huang*, Le Xu, and Wei-Tek Tsai* Summary: In this project, we developed a vLab system, which provides the following features: (a) a reconfigurable networking environment that is capable of creating various types of networks and allows students to experience real-world computer networking a...

متن کامل

AndroDialysis: Analysis of Android Intent Effectiveness in Malware Detection

The wide popularity of Android systems has been accompanied by increase in the number of malware targeting these systems. This is largely due to the open nature of the Android framework that facilitates the incorporation of third-party applications running on top of any Android device. Inter-process communication is one of the most notable features of the Android framework as it allows the reus...

متن کامل

Android Collusive Data Leaks with Flow-sensitive DIALDroid Dataset

We present DIALDroid, a scalable and accurate tool for analyzing inter-app Inter-Component Communication (ICC) among Android apps, which outperforms current state-of-theart ICC analysis tools. Using DIALDroid, we performed the first large-scale detection of collusive and vulnerable apps based on inter-app ICC data flows among 110,150 real-world apps and identified key security insights.

متن کامل

Poster: Android Collusive Data Leaks with Flow-sensitive DIALDroid Dataset

We present DIALDroid, a scalable and accurate tool for analyzing inter-app Inter-Component Communication (ICC) among Android apps, which outperforms current stateof-the-art ICC analysis tools. Using DIALDroid, we performed the first large-scale detection of collusive and vulnerable apps based on inter-app ICC data flows among 110,150 real-world apps and identified key security insights.

متن کامل

Intentio Ex Machina: Android Intent Access Control via an Extensible Application Hook

Android's intent framework serves as the primary method for interprocess communication (IPC) among apps. The increased volume of intent IPC present in Android devices, coupled with intent's ability to implicitly nd valid receivers for IPC, bring about new security challenges. We propose Intentio Ex Machina (IEM), an access control solution for Android intent security. IEM separates the logic fo...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Journal of Computer Security

دوره 24  شماره 

صفحات  -

تاریخ انتشار 2016