论文部分内容阅读
与传统计算平台相比,移动平台拥有大量涉及用户隐私的私密信息.随着Android移动平台日趋流行和应用商城模式的普及,如何保护用户隐私这一安全性课题日益受到关注.本文发现当前Android日志系统存在泄漏用户隐私数据的安全性风险,设计并实现了一个基于静态信息流分析的Android应用程序检测工具LogMiner,用于辅助应用商城在应用发布时的安全性检测工作.LogMiner对200个Android应用程序进行检测,成功分析177个应用,平均每个应用分析时间为4.3分钟,其中33个应用中存在日志安全性隐患,占总数的18.6%.这一结果表明现实生活中的Android应用程序的确存在着这类安全隐患.最后,本文对现有日志系统提出了改进方案.
Compared with the traditional computing platform, mobile platform has a lot of private information involving the privacy of users.With the growing popularity of Android mobile platform and the popularity of the application store mode, how to protect the privacy of users is a security topic of increasing concern.This paper found that the current Android log The system has the risk of leakage of user privacy data security and designs and implements an Android application detection tool LogMiner based on static information flow analysis to assist the application mall in the application release security detection work.LogMiner of 200 Android applications 177 applications were successfully analyzed, with an average analysis time of 4.3 minutes per application, of which 33 were log security vulnerabilities, accounting for 18.6% of the total, indicating that real-world Android applications do exist This type of security risks.Finally, this paper proposed an improved solution to the existing log system.