ID | 60839 |
FullText URL | |
Author |
Yu, Jing
Graduate School of Natural Science and Technology, Okayama University
Yamauchi, Toshihiro
Graduate School of Natural Science and Technology, Okayama University
ORCID
Kaken ID
publons
researchmap
|
Abstract | Android applications that using WebView can load and display web pages. Interaction with web pages allows JavaScript code within the web pages to access resources on the Android device by using the Java object, which is registered into WebView. If this WebView feature were exploited by an attacker, JavaScript code could be used to launch attacks, such as stealing from or tampering personal information in the device. To address these threats, we propose an access control on the security-sensitive APIs at the Java object level. The proposed access control uses static analysis to identify these security-sensitive APIs, detects threats at runtime, and notifies the user if threats are detected, thereby preventing attacks from web pages.
|
Keywords | Android
WebView
static analysis
access control
|
Published Date | 2015
|
Publication Title |
IEICE Transactions on Information and Systems
|
Volume | volumeE98D
|
Issue | issue4
|
Publisher | The Institute of Electronics, Information and Communication Engineers
|
Start Page | 807
|
End Page | 811
|
ISSN | 1745-1361
|
Content Type |
Journal Article
|
language |
English
|
OAI-PMH Set |
岡山大学
|
Copyright Holders | © 2015 The Institute of Electronics, Information and Communication Engineers
|
File Version | publisher
|
DOI | |
Web of Science KeyUT | |
Related Url | isVersionOf https://doi.org/10.1587/transinf.2014ICL0001
|