4.5 Article

DELDROID: An automated approach for determination and enforcement of least-privilege architecture in android

Journal

JOURNAL OF SYSTEMS AND SOFTWARE
Volume 149, Issue -, Pages 83-100

Publisher

ELSEVIER SCIENCE INC
DOI: 10.1016/j.jss.2018.11.049

Keywords

Android security; Software architecture; Multiple-Domain-Matrix (MDM)

Funding

  1. National Science Foundation [CCF-1755890, CCF-1618132, CCF-1252644]
  2. Army Research Office [W911NF-09-1-0273]
  3. Department of Homeland Security [HSHQDC-14-C-B0040]
  4. Air Force Office of Scientific Research [FA95501610030]

Ask authors/readers for more resources

Android is widely used for the development and deployment of autonomous and smart systems, including software targeted for loT and mobile devices. Security of such systems is an increasingly important concern. Android relies on a permission model to secure the system's resources and apps. In Android, since the permissions are granted at the granularity of apps, and all components in an app inherit those permissions, an app's components are over-privileged, i.e., components are granted more privileges than they actually need. Systematic violation of least-privilege principle in Android is the root cause of many security vulnerabilities. To mitigate this issue, we have developed DELDROID, an automated system for determination of least privilege architecture in Android and its enforcement at runtime. A key contribution of DELDROID is the ability to limit the privileges granted to apps without modifying them. DELDROID utilizes static analysis techniques to extract the exact privileges each component needs. A Multiple-Domain Matrix representation of the system's architecture is then used to automatically analyze the security posture of the system and derive its least-privilege architecture. Our experiments on hundreds of real-world apps corroborate DELDkow's ability in effectively establishing the least-privilege architecture and its benefits in alleviating the security threats. (C) 2018 Elsevier Inc. All rights reserved.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.5
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available