Please use this identifier to cite or link to this item: doi:10.22028/D291-25206
Title: AppGuard - real-time policy enforcement for third-party applications
Author(s): Backes, Michael
Gerling, Sebastian
Hammer, Christian
Maffei, Matteo
von Styp-Rekowsky, Philipp
Language: English
Year of Publication: 2012
SWD key words: Echtzeitsystem
Free key words: operating system
DDC notations: 004 Computer science, internet
Publikation type: Report
Abstract: Android has become the most popular operating system for mobile devices, which makes it a prominent target for malicious software. The security concept of Android is based on app isolation and access control for critical system resources. However, users can only review and accept permission requests at install time, or else they cannot install an app at all. Android neither supports permission revocation after the installation of an app, nor dynamic permission assignment. Additionally, the current permission system is too coarse for many tasks and cannot easily be refined. We present an inline reference monitor system that overcomes these deficiencies. It extends Android’s permission system to impede overly curious behaviors; it supports complex policies, and mitigates vulnerabilities of third-party apps and the OS. It is the first solution that provides a practical extension of the current Android permission system as it can be deployed to all Android devices without modification of the firmware or root access to the smartphone. Our experimental analysis shows that we can remove permissions for overly curious apps as well as defend against several recent real-world attacks on Android phones with very little space and runtime overhead. AppGuard is available from the Google Play market.
Link to this record: urn:nbn:de:bsz:291-scidok-49028
hdl:20.500.11880/25262
http://dx.doi.org/10.22028/D291-25206
Series name: Technischer Bericht / A / Fachbereich Informatik, Universität des Saarlandes
Series volume: 2012/02
Date of registration: 16-Jul-2012
Faculty: SE - Sonstige Einrichtungen
Department: SE - Max-Planck-Institut für Informatik
MI - Informatik
Collections:SciDok - Der Wissenschaftsserver der Universität des Saarlandes

Files for this record:
File Description SizeFormat 
android_irm.pdf1,25 MBAdobe PDFView/Open


Items in SciDok are protected by copyright, with all rights reserved, unless otherwise indicated.