HOW TO VIOLATE ANDROID’S PERMISSION SYSTEM WITHOUT VIOLATING IT

Kyoung Soo Han, Biao Jiang Yeoreum Lee · International Conference on Digital Information Processing and Communications · 2013

Android uses permissions for application security management. Android also allows inter-application communication (IAC) which enables cooperation between different applications to perform complex tasks and is a major feature that differentiates Android from its competitors. However, IAC also facilitates malicious applications to collude in an attack of privilege escalation. In this paper, we demonstrate by case studies that all IAC channels can be potentially utilized for privilege escalation attacks, and propose refinement to solve this problem by taking IAC as permissions and exposing IAC to users.

Read the paper · More papers on PaperTik