arrow
返回

Android Custom Permissions Demystified: A Comprehensive Security Evaluation

delete2022-11-01
delete4
PRE
AI
R
Rui Li
W
Wenrui Diao *
Z
Zhou Li
S
Shishuai Yang
S
Shuang Li
S
Shanqing Guo
DOI:10.1109/TSE.2021.3119980delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Permission is the fundamental security mechanism for protecting user data and privacy on Android. Given its importance, security researchers have studied the design and usage of permissions from various aspects. However, most of the previous research focused on the security issues of system permissions. Overlooked by many researchers, an app can use custom permissions to share its resources and capabilities with other apps. However, the security implications of using custom permissions have not been fully understood. In this paper, we systematically evaluate the design and implementation of Android custom permissions. Notably, we built an automatic fuzzing tool, called CuPerFuzzer+, to detect custom permission related vulnerabilities existing in the Android OS. CuPerFuzzer+ treats the operations of the permission mechanism as a black-box and executes massive targeted test cases to trigger privilege escalation. In the experiments, CuPerFuzzer+ discovered 5,932 effective cases with 47 critical paths successfully. Through investigating these vulnerable cases and analyzing the source code of Android OS, we further identified a series of severe design shortcomings lying in the Android permission framework, including dangling custom permission, inconsistent permission-group mapping, custom permission elevating, inconsistent permission definition, dormant permission group, and inconsistent permission type. Exploiting these shortcomings, a malicious app can access unauthorized platform resources. On top of these observations, we propose three general design guidelines to secure custom permissions. Our findings have been acknowledged by the Android security team and assigned CVE-2020-0418, CVE-2021-0306, CVE-2021-0307, and CVE-2021-0317.
Keyword:
Smart phones
Security
Runtime
Tools
Fuzzing
Philosophical considerations
Design methodology
Android security
custom permission
automatic analysis

期刊

IEEE Transactions on Software Engineering 封面图
IEEE Transactions on Software Engineering
IF:
5.6
论文数:
2.9K
被引数:
1.1W

机构

S
shandong university
学者数:
9.5W
论文数: 6.4W
被引数: 94
引用论文

引用论文

Residential Greenness and Long-term Mortality Among Patients Who Underwent Coronary Artery Bypass Graft Surgery
err2023-10-10
err0
PREAI
errMaya Sadeh; Nir Fulman; Nirit Agay; Ilan Levy; Arnona Ziv; Alexandra Chudnovsky; Michael Brauer; Rachel Dankner
err分享
err收藏
Developing Interventions for Frailty
err2015-02-03
err0
errOAAI
errIan D. Cameron; Nicola Fairhall; Liz Gill; Keri Lockwood; Colleen Langron; Christina Aggar; Noeline Monaghan; Susan Kurrle
err分享
err收藏
Genomewide Analysis of mRNA Processing in Yeast Using Splicing-Specific Microarrays
err2002-05-03
err0
PREAI
errTyson A. Clark; Charles W. Sugnet; Manuel Ares
err分享
err收藏
Tissue Origins and Interactions in the Mammalian Skull Vault
err2002-01-01
err0
errOAAI
errXiaobing Jiang; Sachiko Iseki; Robert E. Maxson; Henry M. Sucov; Gillian M. Morriss-Kay
err分享
err收藏
学者 查看更多内容