Background
Type: Article

Towards a Formal Approach for Detection of Vulnerabilities in the Android Permissions System

Journal: The Isc International Journal Of Information Security (20082045)Year: 2022Volume: 14Issue: 3 Special IssuePages: 61 - 69
Torkladani B.aSayyadabdi A. Zamani B.Sayyadabdi A.Torkladani B.a Zamani B.
DOI:10.22042/isecure.2022.14.3.7Language: English

Abstract

Android is a widely used operating system that employs a permission-based access control model. The Android Permissions System (APS) is responsible for mediating application resource requests. APS is a critical component of the Android security mechanism; hence, a failure in the design of APS can potentially lead to vulnerabilities that grant unauthorized access to resources by malicious applications. In this paper, we present a formal approach for modeling and verifying the security properties of APS. We demonstrate the usability of the proposed approach by showcasing the detection of a well-known vulnerability found in Android’s custom permissions. © 2022 ISC. All rights reserved.


Author Keywords

Android SecurityFormal MethodsVerification