Towards a Formal Approach for Detection of Vulnerabilities in the Android Permissions System

08/23/2022
by   Amirhosein Sayyadabdi, et al.
0

Android is a widely used operating system that employs a permission-based access control model. The Android Permissions System (APS) is responsible for mediating application resource requests. APS is a critical component of the Android security mechanism; hence, a failure in the design of APS can potentially lead to vulnerabilities that grant unauthorized access to resources by malicious applications. In this paper, we present a formal approach for modeling and verifying the security properties of APS. We demonstrate the usability of the proposed approach by showcasing the detection of a well-known vulnerability found in Android's custom permissions.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/18/2022

A Framework for Formal Specification and Verification of Security Properties of the Android Permissions System

Android is a widely deployed operating system that employs a permission-...
research
04/12/2022

ASVAAN: Semi-automatic side-channel analysis of Android NDK

Android is the most popular operating systems for smartphones and is als...
research
10/08/2012

Mining Permission Request Patterns from Android and Facebook Applications (extended author version)

Android and Facebook provide third-party applications with access to use...
research
01/11/2019

ACMiner: Extraction and Analysis of Authorization Checks in Android's Middleware

Billions of users rely on the security of the Android platform to protec...
research
02/27/2023

PolyScope: Multi-Policy Access Control Analysis to Triage Android Scoped Storage

Android's filesystem access control is a crucial aspect of its system in...
research
01/23/2019

PINPOINT: Efficient and Effective Resource Isolation for Mobile Security and Privacy

Virtualization is frequently used to isolate untrusted processes and con...
research
10/11/2021

Towards a Principled Approach for Dynamic Analysis of Android's Middleware

The Android middleware, in particular the so-called systemserver, is a c...

Please sign up or login with your details

Forgot password? Click here to reset