摘要
Android平台的应用安全问题日益引起大家的重视,用户隐私泄漏显得尤其严重。本文从代码层面对常见的隐私信息读取以及泄露方式进行了研究并提出了相应的代码特征。提出了一种新的基于代码静态分析技术检测Android应用隐私泄露的方案。该方案基于DTS静态分析框架进行了改造,将隐私泄露作为一类缺陷模式,进而实现了检测Android应用的隐私泄露的系统,并进行了实验验证。
Security of Android applications causes people's attention increasingly,especially user privacy leakage.This article studies the common privacy information read and leak mode form code level and puts forward the corresponding code features.This paper proposes a new solution based on static analysis technical to detect android applications' privacy leakage.The scheme reforms the framework based on DTS static analysis and considers privacy leakage as a kind of defect mode,so as to realize the detection of Android applications privacy leakage system.At last,validate the system by experiment.
出处
《软件》
2012年第10期1-5,共5页
Software
基金
国家"八六三"高技术研究发展计划基金项目(2012AA011201)