GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Software Engineering
  • P215 - Software Engineering 2013 Workshopband (inkl. Doktorandensymposium)
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Software Engineering
  • P215 - Software Engineering 2013 Workshopband (inkl. Doktorandensymposium)
  • Dokumentanzeige

How useful are existing monitoring languages for securing android apps?

Autor(en):
Arzt, Steven [DBLP] ;
Falzon, Kevin [DBLP] ;
Follner, Andreas [DBLP] ;
Rasthofer, Siegfried [DBLP] ;
Bodden, Eric [DBLP] ;
Stolz, Volker [DBLP]
Zusammenfassung
The Android operating system is currently dominating the mobile device market in terms of penetration and growth rate. An important contributor to its success are a wealth of cheap and easy-to-install mobile applications, known as apps. Today, installing untrusted apps is the norm, though this comes with risks: malware is ubiquitous and can easily leak confidential and sensitive data. In this work, we investigate the extent to which we can specify complex information flow properties using existing specification languages for runtime monitoring, with the goal to encapsulate potentially harmful apps and prevent private data from leaking. By modelling a set of representative, Android-specific security policies with Tracematches, JavaMOP, Dataflow Pointcuts and PQL, we are able to identify policylanguage features that are crucial for effectively defining runtime-enforceable Android security properties. Our evaluation demonstrates that while certain property languages suit our purposes better than others, they all lack essential features that would, if present, allow users to provide effective security guarantees about apps. We discuss those shortcomings and propose several possible mechanisms to overcome them.
  • Vollständige Referenz
  • BibTeX
Arzt, S., Falzon, K., Follner, A., Rasthofer, S., Bodden, E. & Stolz, V., (2013). How useful are existing monitoring languages for securing android apps?. In: Wagner, S. & Lichter, H. (Hrsg.), Software Engineering 2013 - Workshopband. Bonn: Gesellschaft für Informatik e.V.. (S. 107-122).
@inproceedings{mci/Arzt2013,
author = {Arzt, Steven AND Falzon, Kevin AND Follner, Andreas AND Rasthofer, Siegfried AND Bodden, Eric AND Stolz, Volker},
title = {How useful are existing monitoring languages for securing android apps?},
booktitle = {Software Engineering 2013 - Workshopband},
year = {2013},
editor = {Wagner, Stefan AND Lichter, Horst} ,
pages = { 107-122 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
107.pdf155.8Kb PDF Öffnen

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

ISBN: 978-3-88579-609-1
ISSN: 1617-5468
Datum: 2013
Sprache: en (en)
Typ: Text/Conference Paper
Sammlungen
  • P215 - Software Engineering 2013 Workshopband (inkl. Doktorandensymposium) [59]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.