android系统上权限提升的安全增强框架
Security Enhanced Framework for Privilege Escalation on Android
安卓系统的安全体系基于传统Unix系统的任意访问控制机制,利用它来进行应用间的沙箱隔离。然而该机制本身存在种种不足,无法应对当今种类繁多的安全威胁。许多工作试图对安卓的安全机制进行扩展,但没有被官方接受。SELinux是一种强制访问控制机制,目前已被集成在安卓的官方代码中。本文提出了一种基于SELinux的权限提升的安全增强框架,可以保证已获得特权的应用只能进行有限的特权操作,对该框架进行了验证并给出结果,最后指出了工作的继续方向。
ndroid security system based on discretionary access control mechanism of traditional Unix systems, leverage it for the sandbox isolation between applications. However, there are inherent shortcoming of this mechanism that it is not enough to deal with today's wide range of security threats. A lot of work trying to extend security mechanisms of Android, but has not been officially accepted. SELinux is a mandatory access control mechanism, which has now been integrated in the source code of Android. This paper presents a framework based on SELinux for securiting privilege escalation, it guarantee privileged applications run only on a limit set of known operation, then framework has been validated and the results are given, finally the future work has been pointed out.
漆涛、吴培君
计算技术、计算机技术
数据安全与计算机安全安卓系统权限提升
Information SecurityAndroid SystemPrivilege Escalation
漆涛,吴培君.android系统上权限提升的安全增强框架[EB/OL].(2013-12-26)[2025-08-16].http://www.paper.edu.cn/releasepaper/content/201312-894.点此复制
评论