Smartphones contain the personal data of the user which it is usually very sensitive and crucial. Unfortunately, this data becomes the target of hackers. Therefore, there is a need to be careful about the type of the released information on Android app users. Sometimes it is difficult to control privacy leakage because many other applications required access to this information for legitimate features. Such as the applications that involve about sharing personal information between users in various locations. Sharing the personal information among the application can cause disclosure of this information. Therefore, a control solution of APIs functions for Android applications that need authorized access to the personal information of the user must be proposed. The present study investigates varieties of related solutions, provides an analysis, and highlights some of their failures and limitations. Therefore, we propose a framework to rewrite Android applications to effectively apply control to each application individually without needing to modify the android system. Moreover, our framework applies context-aware security policies of Android applications in order to control privacy leaks between different Android applications that share the same resources. As a result, modified applications will be forced to communicate with our centralized application monitor to define secure control policies based on our policy specification language to allow users to interpret and apply their complex security policies on their Android applications.
| Date | 27 Mar 2018 |
|---|
| Original language | French |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Chamseddine Talhi (Supervisor) |
|---|
Elarbi, M. (Author),
Talhi (Supervisor),
27 Mar 2018Student thesis: Master's thesis › Master in Engineering: Engineering