国产bbaaaaa片,成年美女黄网站色视频免费,成年黄大片,а天堂中文最新一区二区三区,成人精品视频一区二区三区尤物

首頁> 外文學(xué)位 >Practical Dynamic Information-Flow Tracking on Mobile Devices.
【24h】

Practical Dynamic Information-Flow Tracking on Mobile Devices.

機(jī)譯:在移動(dòng)設(shè)備上的實(shí)用動(dòng)態(tài)信息流跟蹤。

獲取原文
獲取原文并翻譯 | 示例

摘要

Today's consumer mobile platforms such as Android and iOS manage large ecosystems of untrusted third-party applications. It is common for an application to request one or more types of sensitive data. Unfortunately, users have no insight into how their data is used. Given the sensitivity of the data accessible by these applications, it is paramount that mobile operating systems prevent apps from leaking it.;This dissertation shows that it is possible to improve the soundness of dynamic information-flow tracking on a mobile device without sacrificing precision, performance, or transparency. We extend the state of the art in dynamic information-flow tracking on Android and address two major limitations: quantifying implicit flow leaks in Dalvik bytecode and tracking explicit flows in native code. Our goal is to deliver seamless end-to-end taint tracking across Dalvik bytecode and native code.;We propose SpanDex, a system that quantifies implicit flow leaks in Dalvik bytecode for apps handling password data. SpanDex computes a bound of revealed tainted data by recording the control-flow dependencies and for each password character, keeps track of the possible set of values that have been inferred. We also propose TaintTrap, a taint tracking system for native code in third party apps. We explore native taint tracking performance bottlenecks and hardware acceleration techniques to improve instrumentation performance.
機(jī)譯:當(dāng)今的消費(fèi)者移動(dòng)平臺(tái)(例如Android和iOS)管理著不受信任的第三方應(yīng)用程序的大型生態(tài)系統(tǒng)。應(yīng)用程序通常要求一種或多種類型的敏感數(shù)據(jù)。不幸的是,用戶無法了解其數(shù)據(jù)的使用方式??紤]到這些應(yīng)用程序可訪問的數(shù)據(jù)的敏感性,移動(dòng)操作系統(tǒng)防止應(yīng)用程序泄漏數(shù)據(jù)至關(guān)重要。該論文表明,可以在不犧牲精度的情況下提高移動(dòng)設(shè)備上動(dòng)態(tài)信息流跟蹤的可靠性,性能或透明度。我們?cè)贏ndroid上的動(dòng)態(tài)信息流跟蹤中擴(kuò)展了現(xiàn)有技術(shù),并解決了兩個(gè)主要限制:量化Dalvik字節(jié)碼中的隱式流泄漏和跟蹤本機(jī)代碼中的顯式流。我們的目標(biāo)是在Dalvik字節(jié)碼和本機(jī)代碼之間實(shí)現(xiàn)無縫的端到端污點(diǎn)跟蹤。我們提出了SpanDex,該系統(tǒng)可以量化Dalvik字節(jié)碼中隱式的流泄漏,用于處理密碼數(shù)據(jù)的應(yīng)用程序。 SpanDex通過記錄控制流相關(guān)性來計(jì)算揭示的污染數(shù)據(jù)的范圍,并針對(duì)每個(gè)密碼字符,跟蹤已推斷出的可能值集。我們還建議使用TaintTrap,這是第三方應(yīng)用程序中本機(jī)代碼的污染跟蹤系統(tǒng)。我們探索原生污點(diǎn)跟蹤性能瓶頸和硬件加速技術(shù),以提高儀器性能。

著錄項(xiàng)

  • 作者

    Pistol, Valentin.;

  • 作者單位

    Duke University.;

  • 授予單位 Duke University.;
  • 學(xué)科 Computer science.;Computer engineering.
  • 學(xué)位 Ph.D.
  • 年度 2014
  • 頁碼 105 p.
  • 總頁數(shù) 105
  • 原文格式 PDF
  • 正文語種 eng
  • 中圖分類
  • 關(guān)鍵詞

相似文獻(xiàn)

  • 外文文獻(xiàn)
  • 中文文獻(xiàn)
  • 專利
獲取原文

客服郵箱:kefu@zhangqiaokeyan.com

京公網(wǎng)安備:11010802029741號(hào) ICP備案號(hào):京ICP備15016152號(hào)-6 六維聯(lián)合信息科技 (北京) 有限公司?版權(quán)所有
  • 客服微信

  • 服務(wù)號(hào)