このエントリーをはてなブックマークに追加
ID 60837
フルテキストURL
著者
Yu, Jing Graduate School of Natural Science and Technology, Okayama University
Yamauchi, Toshihiro Graduate School of Natural Science and Technology, Okayama University ORCID Kaken ID publons researchmap
抄録
Android applications that using WebView can load and display web pages. Furthermore, by using the APIs provided in WebView, Android applications can interact with web pages. The interaction allows JavaScript code within the web pages to access resources on the Android device by using the Java object, which is registered into WebView. If this WebView feature were exploited by an attacker, JavaScript code could be used to launch attacks, such as stealing from or tampering personal information in the device. To address these threats, we propose a method that performs access control on the security-sensitive APIs at the Java object level. The proposed method uses static analysis to identify these security-sensitive APIs, detects threats at runtime, and notifies the user if threats are detected, thereby preventing attacks from web pages.
キーワード
Java
Androids
Humanoid robots
Web pages
Smart phones
Assembly
Browsers
備考
Published in: 2013 IEEE 10th International Conference on High Performance Computing and Communications & 2013 IEEE International Conference on Embedded and Ubiquitous Computing
発行日
2013
出版物タイトル
2013 IEEE 10th International Conference on High Performance Computing and Communications & 2013 IEEE International Conference on Embedded and Ubiquitous Computing
出版者
IEEE
開始ページ
1628
終了ページ
1633
ISBN
978-0-7695-5088-6
資料タイプ
会議発表論文
オフィシャル URL
https://ieeexplore.ieee.org/document/6832111
言語
英語
論文のバージョン
author
DOI
Web of Science KeyUT