作者
Zhui Deng, Brendan Saltaformaggio, Xiangyu Zhang, Dongyan Xu
发表日期
2015/10/12
研讨会论文
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS '15)
页码范围
44-56
简介
With the booming sale of iOS devices, the number of iOS applications has increased significantly in recent years. To protect the security of iOS users, Apple requires every iOS application to go through a vetting process called App Review to detect uses of private APIs that provide access to sensitive user information. However, recent attacks have shown the feasibility of using private APIs without being detected during App Review. To counter such attacks, we propose a new iOS application vetting system, called iRiS, in this paper. iRiS first applies fast static analysis to resolve API calls. For those that cannot be statically resolved, iRiS uses a novel iterative dynamic analysis approach, which is slower but more powerful compared to static analysis. We have ported Valgrind to iOS and implemented a prototype of iRiS on top of it. We evaluated iRiS with 2019 applications from the official App Store. From these, iRiS …
引用总数
201620172018201920202021202220232024138101073792
学术搜索中的文章
Z Deng, B Saltaformaggio, X Zhang, D Xu - Proceedings of the 22nd ACM SIGSAC Conference on …, 2015