刘长江

个人信息Personal Information

教授 硕士生导师

招生学科专业:
教育管理 -- 【招收硕士研究生】 -- 人文与社会科学学院
课程与教学论 -- 【招收硕士研究生】 -- 外国语学院
外国语言文学 -- 【招收硕士研究生】 -- 外国语学院
英语笔译 -- 【招收硕士研究生】 -- 外国语学院

主要任职:校学术委员会委员,校教学委员会委员

其他任职:江苏省翻译协会常务理事,江苏省外国语言学会理事,外语教学技术专委会理事

性别:男

毕业院校:四川大学,上海外国语大学

学历:上海外国语大学

学位:文学博士学位

所在单位:外国语学院/教务处

办公地点:将军路校区东区外语楼401

联系方式:liucj@nuaa.edu.cn

电子邮箱:

扫描关注

论文成果

当前位置: 中文主页 >> 科学研究 >> 论文成果

Detect Storage Vulnerability of User-Input Privacy in Android Applications with Static and Dynamic Analysis

点击次数:

所属单位:计算机科学与技术学院/人工智能学院/软件学院

发表刊物:CLOUD COMPUTING AND SECURITY, PT II

关键字:Android security Privacy protection Static and dynamic analysis Smali instrumentation Storage vulnerability

摘要:In recent years Android has become the most popular operating system in mobile phone, and a variety of apps bring people great convenience in our daily life and work. Due to the resource constraints in mobile phone and user experience considerations, a large number of private data are stored in the phone itself. Privacy Leaks will bring huge losses to us. EditText, which is designed for Android developers to input the sensitive data (e.g. username, password, search keywords etc.) to the apps, carries much User-Input Privacy (UIP) data. So, whether these UIP data is stored in the phone safely becomes the key to protect the privacy. In this paper, we do the research about the UIP data in EditText widget, and detect whether the data entered by the user is safely stored through static taint analysis and dynamic Smali Instrumentation. Experiments show that some of the apps store the UIP data in EditText at an unsafe location or store them in a weak way, which will bring the risk of privacy leakage.

ISSN号:0302-9743

是否译文:

发表时间:2017-01-01

合写作者:庄毅

通讯作者:刘长江