PhoneWrap - Injecting the "How Often" into Mobile Apps

Daniel Franzén, David Aspinall · Edinburgh Research Explorer (University of Edinburgh) · 2016

Mobile apps have access to a variety of sensitive resources and data. Current permission based policies guarding these resources are not expressive enough to distinguish the wanted functionality from malicious attacks. We present the tool PhoneWrap which inserts fine-grained ticket-based policies into mobile JavaScript apps written with the PhoneGap framework. Our policies grant a bounded number of accesses for each functionality based on the user’s interaction with the app. The policies are enforced without modification of the execution environment. We have applied PhoneWrap successfully to hand-crafted examples and real-world Android apps to show that accurate policies can be retrofitted.

Read the paper · More papers on PaperTik