Skip to main navigation Skip to search Skip to main content

Privilege Leakage and Information Stealing through the Android Task Mechanism

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

To facilitate apps to collaborate in finish complex jobs, Android allows isolated apps to communicate through explicit interfaces. However, the communication mechanisms often give additional privilege to apps, which can be exploited by attackers. The Android Task Structure is a widely-used mechanism to facilitate apps' collaboration. Recent research has identified attacks to the mechanism, allowing attackers to spoof UIs in Android. In this paper, we present an analysis on the security of Android task structure. In particular, we analyze the system/app conditions that can cause the task mechanism to leak privilege. Furthermore, we identify new end-to-end attacks that enable attackers to actively interfere with victim apps to steal sensitive information. Based on our findings, we also develop atask interference checking app for exploits to the Android task structure. © 2017 IEEE.
Original languageEnglish
Title of host publicationProceedings - 2017 IEEE Symposium on Privacy-Aware Computing, PAC 2017
PublisherIEEE
Pages152-163
Volume2017-January
ISBN (Print)9781538610275
DOIs
Publication statusPublished - 4 Dec 2017
Externally publishedYes
Event1st IEEE Symposium on Privacy-Aware Computing, PAC 2017 - Washington, United States
Duration: 1 Aug 20173 Aug 2017

Publication series

NameProceedings - 2017 IEEE Symposium on Privacy-Aware Computing, PAC 2017
Volume2017-January

Conference

Conference1st IEEE Symposium on Privacy-Aware Computing, PAC 2017
PlaceUnited States
CityWashington
Period1/08/173/08/17

Bibliographical note

Publication details (e.g. title, author(s), publication statuses and dates) are captured on an “AS IS” and “AS AVAILABLE” basis at the time of record harvesting from the data source. Suggestions for further amendments or supplementary information can be sent to [email protected].

Funding

This work was supported in part by the National Natural Science Foundation of China (No. 61402029), the National Natural Science Foundation of China (No. 61370190 and No. 61379002), Singapore Ministry of Education under NUS grant R-252-000-539-112.

Fingerprint

Dive into the research topics of 'Privilege Leakage and Information Stealing through the Android Task Mechanism'. Together they form a unique fingerprint.

Cite this