摘要
针对智能手机普及带来的第三方应用程序中大量隐私信息泄露及权限滥用问题,采用静态分析技术,逆向反编译解析APK文件,检测应用程序是否存在泄露用户隐私和滥用手机权限。提出采取安装应用程序之前展示可能涉及的权限和API的方法,为用户选择提供参考依据,从而解决隐私信息泄露和权限滥用问题。
In terms of a large number of privacy information leaks and permissions abuses in the third party applications which are brought by the popularity of smart phones, static analysis technology and the reverse decompile of APK files are utilized to dectect whether there are leaks of privacy information and the abuse of permissions in application programs. A solution is proposed to demonstrate permissions and API that possibly are involved before installing an application. It helps to provide references for the users to select, so that the problem of privacy information leaks and permissions abuses can be solved.
作者
曹勇
李军虎
陈晓升
CAO Yong;LI Junhu;CHEN Xiaosheng(Information Security Department,Naval University of Engineering,Wuhan 430033;No.92665 Troops ofPLA,Cili 427200;No.91650Troops of PLA,Zhanjiang 524000)
出处
《计算机与数字工程》
2018年第10期2146-2150,共5页
Computer & Digital Engineering