Application-centric security policies on unmodified Android
Nikhilesh Reddy, Jinseong Jeon, Jeffrey A. Vaughan, Todd D. Millstein, Jeffrey S. Foster · 2011
AbstractGoogle’s Android platform uses a fairly standard resource-centric permission model toprotect resources such as the camera, GPS, and Internet connection. We claim that a much bet-ter permission model for developers and users would be application-centric, with a vocabularythat directly relates to application-level functionality, e.g., one permission could allow camerause, but only for barcode scanning; another could allow Internet access, but only to certain do-mains. Despite the large apparent gap between resource- and application-centric permissions,we argue that Android already provides the necessary mechanisms to support an expressiveand practical form of application-centric policies. Specifically, each application-centric per-mission can be represented by a new Android permission and can be enforced by coupling thepermission with a trusted service running in its own process. We present a survey of the top 24free Android apps and show that a small vocabulary of application-centric permissions coversmuch of the functionality of those apps. We also describe a prototype implementation of ourapproach.