Technical Report: Towards Unied Authorization for Android ?
Michael J. May, Karthik Bhargavan · 2013
Android applications that manage sensitive data such as email and les downloaded from cloud storage services need to protect their data from malware installed on the phone. While prior security analyses have focused on protecting system data such as GPS locations from malware, not much attention has been given to the protection of ap- plication data. We show that many popular commercial applications in- correctly use Android authorization mechanisms leading to attacks that steal sensitive data. We argue that formal verication of application be- haviors can reveal such errors and we present a formal model in ProVerif that accounts for a variety of Android authorization mechanisms and system services. We write models for seven popular applications and an- alyze them with ProVerif to point out attacks. As a countermeasure, we propose Authzoid, a sample standalone application that lets applications dene authorization policies and enforces them on their behalf.