ISCAS OpenIR
Direct Resource Hijacking in Android
Gu, YC; Li, Q; Zhang, HT; Su, PR; Zhang, XW; Feng, DG
2016
发表期刊IEEE INTERNET COMPUTING
ISSN1089-7801
卷号20期号:5页码:46-56
摘要In this article, the authors discuss a new attack called a direct resource hijacking attack (or resource hijacking attack), which directly hijacks exported components or permissions on components owned by benign applications. To tackle this vulnerability, they propose a fine-grained resource access control framework in Android and introduce a certificate-augmented resource naming mechanism. With this method, malicious apps can't hijack a victim app's permissions to steal its private data in the victim app, or hijack a victim app's components to retrieve data that's delivered to the victim app.; In this article, the authors discuss a new attack called a direct resource hijacking attack (or resource hijacking attack), which directly hijacks exported components or permissions on components owned by benign applications. To tackle this vulnerability, they propose a fine-grained resource access control framework in Android and introduce a certificate-augmented resource naming mechanism. With this method, malicious apps can't hijack a victim app's permissions to steal its private data in the victim app, or hijack a victim app's components to retrieve data that's delivered to the victim app.
收录类别SCI
部门归属Chinese Acad Sci, Inst Software, Beijing 100864, Peoples R China. Tsinghua Univ, Grad Sch Shenzhen, Shenzhen, Peoples R China. Indiana Univ, Sch Informat & Comp, Bloomington, IN 47405 USA. Samsung Res Amer, Mountain View, CA USA.
语种英语
WOS记录号WOS:000387067100007
引用统计
被引频次:2[WOS]   [WOS记录]     [WOS相关记录]
内容类型期刊论文
URI标识http://ir.iscas.ac.cn/handle/311060/17307
专题中国科学院软件研究所
推荐引用方式
GB/T 7714
Gu, YC,Li, Q,Zhang, HT,et al. Direct Resource Hijacking in Android[J]. IEEE INTERNET COMPUTING,2016,20(5):46-56.
APA Gu, YC,Li, Q,Zhang, HT,Su, PR,Zhang, XW,&Feng, DG.(2016).Direct Resource Hijacking in Android.IEEE INTERNET COMPUTING,20(5),46-56.
MLA Gu, YC,et al."Direct Resource Hijacking in Android".IEEE INTERNET COMPUTING 20.5(2016):46-56.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Gu, YC]的文章
[Li, Q]的文章
[Zhang, HT]的文章
百度学术
百度学术中相似的文章
[Gu, YC]的文章
[Li, Q]的文章
[Zhang, HT]的文章
必应学术
必应学术中相似的文章
[Gu, YC]的文章
[Li, Q]的文章
[Zhang, HT]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。