標題: DROIT plus : Taint Tracking for Storage Access on Android
作者: Hsu, Chia-Wei
Chang, Chia-Huei
Wang, Chi-Wei
Shieh, Shiuhpyng
資訊工程學系
Department of Computer Science
關鍵字: mobile security;information flow;Android;file system;taint tracking
公開日期: 1-九月-2017
摘要: The leakage of sensitive data has been a major concern in Android ecosystem. Analysts therefore propose dynamical taint tracking to effectively track the data flow of accessed data. However, the off-the-shelf taint tracking systems lack byte-granularity support for storage tracking. In this paper, we propose DROIT+ which uses the fine-grained storage tracking technique to track data flow among Android storages. DROIT+ is able to reveal the composition of data flows. Storage tracking on Android is difficult since data flows of apps may span heterogeneous media including memory, SD cards, NAND Flash, and network adapters. To capture a whole picture of data flows in storage, we formally define data flow and propose our method from both logical and physical perspectives. The method has also been implemented as an extension to the proposed tracking system, DROIT. Two case studies and two benchmark tools are used for the evaluation in terms of storage tracking ability, network tracking ability, and efficiency, respectively. The result shows that DROIT+ provides a better coverage using byte-granularity taint tracking.
URI: http://dx.doi.org/10.6688/JISE.2017.33.5.8
http://hdl.handle.net/11536/146057
ISSN: 1016-2364
DOI: 10.6688/JISE.2017.33.5.8
期刊: JOURNAL OF INFORMATION SCIENCE AND ENGINEERING
Volume: 33
起始頁: 1237
結束頁: 1254
顯示於類別:期刊論文