首页 | 本学科首页   官方微博 | 高级检索  
     

一种基于android轻型网关敏感数据泄露检测模型
引用本文:王进平. 一种基于android轻型网关敏感数据泄露检测模型[J]. 计算机应用研究, 2016, 33(8)
作者姓名:王进平
作者单位:上海理工大学
基金项目:国家自然科学基金资助项目;高等学校博士学科点专项科研基金;上海重点科技攻关项目;上海市工程中心建设项目;上海智能家居大规模物联共性技术工程中心项目;上海市一流学科建设项目;沪江基金研究基地专项
摘    要:针对智慧家居控制系统中基于android系统轻型网关的敏感数据泄露问题,提出了一种基于android本地库层污点传播和应用层控制的分层互连检测模型。通过在IPC Binder通信时标记污点,在待测应用进程调用本地网络套接字函数时检测污点,分析污点传播路径并计算泄露指数,实现对敏感数据泄露的跟踪检测。实验表明该模型能够检测出各个敏感数据源以明文或密文方式的数据泄露,准确率达到93%以上,同时性能开销不超过1%,从而实现对Android轻型网关敏感数据泄露的有效检测,实用性强,并为之后相关研究提供了新方向。

关 键 词:智慧家居   Android轻型网关;污点传播;敏感数据泄露;分层互连检测;明文密文泄露
收稿时间:2015-05-14
修稿时间:2016-06-19

A sensitive data leak detection model based on Android light gateway
wangjinping. A sensitive data leak detection model based on Android light gateway[J]. Application Research of Computers, 2016, 33(8)
Authors:wangjinping
Affiliation:University of Shanghai for Science and Technology
Abstract:The light gateway based on android system in intelligent home control system has the sensitive data leakage problem. This paper proposes a hierarchical and interconnected detection model based on taint spread on android native library layer and control on application layer. Through marking taint during the IPC Binder communication ,detecting taint when the native network socket function called by the being tested application process, analyzing taint propagation path and calculating the leakage index, to realize the track of sensitive data leakage detection . The experiments show that the model can detect the sensitive data leakage in plain text or cipher text form of data breaches, accuracy can reach above 93%, at the same time performance overhead is not more than 1%, As a result, realizing the effective detection of sensitive data leakage of Android light gateway,having strong practivity,and leading a new direction for related research in the future.
Keywords:intelligent home  android light gateway   taint spread   sensitive data leakage   hierarchical and interconnected detection   plain text and cipher text leakage
点击此处可从《计算机应用研究》浏览原始摘要信息
点击此处可从《计算机应用研究》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号