arrow
返回

Is Your Android App Insecure? Patching Security Functions With Dynamic Policy Based on a Java Reflection Technique

delete2020-01-01
delete2
delete
OA
AI
S
Sunghoon Lee
S
Seung-Hyun Kim *
J
Jung Yeon Hwang
S
Soohyung Kim
S
Seunghun Jin
DOI:10.1109/ACCESS.2020.2987059delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
With the popularization of smart devices, companies are adopting bring-your-own-device or mobile office policies that utilize personal smart devices for work. However, as work data are stored on individual smart devices, critical security threats are emerging, such as the leakage of confidential documents. Enterprises want to address this issue by adapting enterprise mobility management (EMM) solutions. Appwrapping is among the core technologies in EMM solutions, enabling security function insertion or misused code patching without the original application (app) source code. Studies on permission control, misused code patching, security function insertion based on static policies, etc., have been conducted, but there are limitations such as poor user convenience and overhead. In this paper, we propose an AppWrapper toolkit to support dynamic polices. Basically it can insert security function execution code into apps by using appwrapping technology without the original source code. This code uses Java reflection to invoke security functions dynamically based on preset policies. Accordingly, after the initial appwrapping, the policy can be changed easily. In addition, even when multiple security functions are required, Java reflection can invoke multiple security functions dynamically and simultaneously without conflicting with the existing code. The AppWrapper toolkit also provides a log function to check in real time where the security function is needed. Hence, the policy-setting administrator can check the log in real time and implement the security function where needed. Our experimental results show that this technique improves significantly the efficiency, effectiveness, and convenience of adding security function execution code.
Keyword:
Security
Androids
Humanoid robots
Java
Reflection
Registers
Privacy
Mobile application
mobile computing
security management
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

U
university of science & technology (ust)
学者数:
2.7K
论文数: 2.0K
被引数: 5
引用论文

引用论文

err分享
err收藏
Progress in the Management of Advanced Thoracic Malignancies in 2017
err2018-03-01
err0
errOAAI
errRoberto Ferrara; Laura Mezquita; Benjamin Besse
err分享
err收藏
A privacy enforcing framework for Android applications
err2016-09-01
err17
errOAAI
errNeisse, Ricardo; Steri, Gary; Geneiatakis, Dimitris; Fovino, Igor Nai
err分享
err收藏
err分享
err收藏
Effect of Different Chelating Agents on the Physicochemical Properties of Cu/ZnO Catalysts for Low-temperature Methanol Synthesis from Syngas Containing CO<sub>2</sub>
err2021-09-01
err0
errOAAI
errFei CHEN; Weizhe GAO; Baizhang ZHANG; Heng ZHAO; Liwei XIAO; Yuya ARAKI; Xiaojing YONG; Wei ZHANG; Tiejian ZHAO; Zhongshan GUO; Yingluo HE; Peipei ZHANG; Noritatsu TSUBAKI
err分享
err收藏
DexMonitor: Dynamically Analyzing and Monitoring Obfuscated Android Applications
err2018-01-01
err15
errOAAI
errCho, Haehyun; Yi, Jeong Hyun; Ahn, Gail-Joon
err分享
err收藏
学者 查看更多内容