Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

DPhil the Future: App users need protecting from aggregation of permissions

Дата публикации: 18-12-2017 12:00:00

To help speed up code writing, many app developers use common libraries, but this can result in such libraries getting access to significant privileges on a device. DPhil student Vincent Taylor describes the problem and his research in the area

Основное содержимое страницы с новостью.

Posted: 18th December 2017

Graphic with a timer on a blue background titled DPhil The Future and the text 'Our students are 100% part of our success. DPhil the Future is our way of giving our students a platform to share their insight and views on all things computer science' To help speed up code writing, many app developers use common libraries, but this can result in such libraries getting access to significant privileges on a device. DPhil student Vincent Taylor describes the problem and his research in the area.

Smartphones have rapidly become a leading part of our daily lives. Smartphone usage is fuelled predominantly by apps, small pieces of software ready to be downloaded from app stores at the touch of a button. Android is the most popular smartphone operating system, with an official app store (Google Play) containing over two million apps.

Each Android app is delivered as a single archive, which contains all app code and resources needed for the app to function. Just as on traditional computers, third-party libraries are available for app developers to use to rapidly deploy advanced functionality to their apps. Common libraries include those for advertising, analytics, and social networking.

The libraries used in Android apps are tightly integrated into the binary code of the app itself and the Android operating system treats an app and its embedded libraries as a single entity. An undesired consequence of this is that embedded libraries obtain the same permissions that have been granted to their host app. This means that granting permissions to apps often grants permissions to other third parties as well.

While this permission leakage from apps to libraries is well understood by Android security and privacy researchers, a far more insidious problem has been left unaddressed. Popular libraries are likely to be used in more than one app on a device. The problem stems from the fact that apps typically have different sets of permissions granted to them. This means that an instance of a library in one app may have several permissions, and another instance of the same library in another app on the same device may have several different permissions. Thus, if the library were to aggregate its permissions, it would achieve significantly more privileges on a device than it would seem at first glance. This is the problem of ‘intra-library collusion’.

Professor Ivan Martinovic and I from Oxford (with data and insights from Alastair Beresford of Cambridge University) studied the potential for intra-library collusion in the real-world using data from 30,000 actual smartphones. Over 57% of devices were susceptible to intra-library collusion. By performing a historical study, we showed that the risks from intra-library collusion have increased significantly over the past two-and-a-half years.

Having investigated the problem, we are now conducting research into providing mitigations for it as part of my DPhil research. The next steps are to extract URLs and network traffic from libraries to see what private data is being sent, and to where. This work fits within the security research theme of the department, which has the aim of enabling users to use technology with confidence that their privacy will not be breached.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1DPhil the Future: Parental control apps: protection or punishment?06.1701-12-2020
2DPhil the Future: Take control of your phone, before it takes control of you06.6608-12-2020
3DPhil the Future: Signal Injection Attacks against CCD Image Sensors09.7408-12-2022
4DPhil the Future: Satellite hacking - researching cyber space07.0304-06-2021
5DPhil the Future: Using Inertial Sensors to Authenticate Users08.6201-06-2023
6DPhil the Future: Who's storing your conversations?07.8406-06-2018
7DPhil the Future: Why We Need Fallible Humans in AI Alignment05.9220-10-2025
8DPhil the Future: Flight simulator evaluates cyber-attack reactions013.4706-06-2018
9DPhil the Future: Wearable Authentication in Mobile Payments using a Smartwatch07.6615-12-2022
10DPhil the Future: Reclaiming data autonomy: the role of Solid in a safer Web07.5506-02-2024

Классификация: Наука. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.44. Источник: www.cs.ox.ac.uk.