RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    JNI 이용 안드로이드 애플리케이션의 개인정보 유출 탐지 = Detecting Personal Information Leaks in Android Application Using JNI

    한글로보기

    https://www.riss.kr/link?id=T15532543

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    The use of smartphones is increasing and the leakage of user personal information is frequently occurring. Taint analysis tools to prevent such leakage of personal information include Flowdroid, Amandroid, and Scandroid, but they analyze Java byte code only, not the native libraries. Even a few methods including Gangjin's research and Argus-SAF, which can analyze the native libraries, may not report correct results depending on the NDK versions. To solve this problem, we converted the native libraries into the LLVM intermediate representations according to the NDK version, and the resulting intermediate representations are analyzed using the taint analysis method. In order to measure the performance improvement of the proposed analyzer, it has experimented with 15 malicious applications and 15 normal applications. Experimental results show that the proposed method is superior to other methods, specifically, it recorded the highest F1-score 60.6% than others, FlowDroid 22.2% and Argus-SAF 41.4%.
    번역하기

    The use of smartphones is increasing and the leakage of user personal information is frequently occurring. Taint analysis tools to prevent such leakage of personal information include Flowdroid, Amandroid, and Scandroid, but they analyze Java byte cod...

    The use of smartphones is increasing and the leakage of user personal information is frequently occurring. Taint analysis tools to prevent such leakage of personal information include Flowdroid, Amandroid, and Scandroid, but they analyze Java byte code only, not the native libraries. Even a few methods including Gangjin's research and Argus-SAF, which can analyze the native libraries, may not report correct results depending on the NDK versions. To solve this problem, we converted the native libraries into the LLVM intermediate representations according to the NDK version, and the resulting intermediate representations are analyzed using the taint analysis method. In order to measure the performance improvement of the proposed analyzer, it has experimented with 15 malicious applications and 15 normal applications. Experimental results show that the proposed method is superior to other methods, specifically, it recorded the highest F1-score 60.6% than others, FlowDroid 22.2% and Argus-SAF 41.4%.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    스마트폰의 사용이 늘고 있고 그에 따른 사용자 개인정보 유출이 빈번하게 일어나고 있다. 이러한 개인정보 유출을 막기 위한 오염 분석 도구로 FlowDroid, AmanDroid, ScanDroid가 있지만 Java 바이트 코드만을 분석하기 때문에 네이티브 라이브러리를 분석하지 못한다. 네이티브 라이브러리를 분석할 수 있는 방법으로 강진의 연구, Arugs-SAF 등이 제안되었지만 NDK 버전에 따라 올바른 결과를 내지 못하는 문제점이 있었다. 이를 해결하기 위해 NDK 버전에 따라 생성되는 네이티브 라이브러리를 LLVM 중간표현으로 변환한 후 LLVM 중간표현에 대한 오염 분석을 수행하였다. 제안한 분석기의 성능 향상을 측정하기 위해 15개의 악성 애플리케이션과 15개의 정상 애플리케이션에 대해 실험하였다. 실험 결과 제안한 방법이 FlowDroid 22.2%, Argus-SAF 41.4%에 비해 가장 높은 F1-점수 60.6%를 기록하였다.
    번역하기

    스마트폰의 사용이 늘고 있고 그에 따른 사용자 개인정보 유출이 빈번하게 일어나고 있다. 이러한 개인정보 유출을 막기 위한 오염 분석 도구로 FlowDroid, AmanDroid, ScanDroid가 있지만 Java 바이트...

    스마트폰의 사용이 늘고 있고 그에 따른 사용자 개인정보 유출이 빈번하게 일어나고 있다. 이러한 개인정보 유출을 막기 위한 오염 분석 도구로 FlowDroid, AmanDroid, ScanDroid가 있지만 Java 바이트 코드만을 분석하기 때문에 네이티브 라이브러리를 분석하지 못한다. 네이티브 라이브러리를 분석할 수 있는 방법으로 강진의 연구, Arugs-SAF 등이 제안되었지만 NDK 버전에 따라 올바른 결과를 내지 못하는 문제점이 있었다. 이를 해결하기 위해 NDK 버전에 따라 생성되는 네이티브 라이브러리를 LLVM 중간표현으로 변환한 후 LLVM 중간표현에 대한 오염 분석을 수행하였다. 제안한 분석기의 성능 향상을 측정하기 위해 15개의 악성 애플리케이션과 15개의 정상 애플리케이션에 대해 실험하였다. 실험 결과 제안한 방법이 FlowDroid 22.2%, Argus-SAF 41.4%에 비해 가장 높은 F1-점수 60.6%를 기록하였다.

    더보기

    목차 (Table of Contents)

    • Ⅰ 서론 1
    • Ⅱ 관련 연구 3
    • 2.1 오염 분석 연구 3
    • 2.1.1 동적 오염 분석 도구 4
    • 2.1.2 정적 오염 분석 도구 8
    • Ⅰ 서론 1
    • Ⅱ 관련 연구 3
    • 2.1 오염 분석 연구 3
    • 2.1.1 동적 오염 분석 도구 4
    • 2.1.2 정적 오염 분석 도구 8
    • 2.1.3 JNI를 고려하는 정적 오염 분석 연구 10
    • 2.2 LLVM 중간표현 리프터 13
    • Ⅲ 도구 분석 16
    • 3.1 Argus-SAF 분석 16
    • 3.1.1 JN-SAF 클라이언트 모듈 16
    • 3.1.2 JN-SAF 서버 모듈 17
    • 3.1.3 NativeDroid 모듈 19
    • 3.1.4 Jawa 모듈 19
    • 3.1.5 Argus-SAF 성능 평가 21
    • 3.2 Retdec 분석 23
    • 3.3 PhASAR 분석 24
    • 3.3.1 값 변경 문제 25
    • 3.3.2 소스 함수 및 자료형 문제 29
    • 3.3.3 엔트리 포인트 문제 30
    • Ⅳ ASAP 설계 및 구현 32
    • 4.1 ASAP 설계 32
    • 4.2 네이티브 분석 모듈 구현 34
    • 4.2.1 RetDec 수정 34
    • 4.2.2 PhASAR 수정 36
    • Ⅴ 실험 39
    • 5.1 ASAP 실험 대상 39
    • 5.2 실험 결과 40
    • 5.3 고찰 43
    • 5.3.1 오염 분석 보조 도구 43
    • 5.3.2 ASAP 적확도 43
    • 5.3.3 정적 오염 분석기 특성 비교 44
    • 5.3.4 상용 도구와 비교 45
    • Ⅵ 결론 47
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼