Access control to prevent malicious javascript code exploiting vulnerabilities of webview in android OS

Research output: Contribution to journalArticle

5 Citations (Scopus)

Abstract

Android applications that using WebView can load and display web pages. Interaction with web pages allows JavaScript code within the web pages to access resources on the Android device by using the Java object, which is registered into WebView. If this WebView feature were exploited by an attacker, JavaScript code could be used to launch attacks, such as stealing from or tampering personal information in the device. To address these threats, we propose an access control on the security-sensitive APIs at the Java object level. The proposed access control uses static analysis to identify these security-sensitive APIs, detects threats at runtime, and notifies the user if threats are detected, thereby preventing attacks from web pages.

Original languageEnglish
Pages (from-to)807-811
Number of pages5
JournalIEICE Transactions on Information and Systems
VolumeE98D
Issue number4
DOIs
Publication statusPublished - Apr 1 2015

Keywords

  • Android, WebView, static analysis, access control

ASJC Scopus subject areas

  • Software
  • Hardware and Architecture
  • Computer Vision and Pattern Recognition
  • Electrical and Electronic Engineering
  • Artificial Intelligence

Fingerprint Dive into the research topics of 'Access control to prevent malicious javascript code exploiting vulnerabilities of webview in android OS'. Together they form a unique fingerprint.

  • Cite this