Draco: A System for Uniform and Fine-grained Access Control for Web Code on Android
Güliz Seray Tuncay, Soteris Demetriou, Carl A. Gunter
摘要
In-app embedded browsers are commonly used by app developers to display web content without having to redirect the user to heavyweight web browsers. Just like the conventional web browsers, embedded browsers can allow the execution of web code. In addition, they provide mechanisms (viz., JavaScript bridges) to give web code access to internal app code that might implement critical functionalities and expose device resources. This is intrinsically dangerous since there is currently no means for app developers to perform origin-based access control on the JavaScript bridges, and any web code running in an embedded browser is free to use all the exposed app and device resources. Previous work that addresses this problem provided access control solutions that work only for apps that are built using hybrid frameworks. Additionally, these solutions focused on protecting only the parts of JavaScript bridges that expose permissions-protected resources. In this work, our goal is to provide a generic solution that works for all apps that utilize embedded web browsers and protects all channels that give access to internal app and device resources. Towards realizing this goal, we built Draco, a uniform and fine-grained access control framework for web code running on Android embedded browsers (viz., WebView). Draco provides a declarative policy language that allows developers to define policies to specify the desired access characteristics of web origins in a fine-grained fashion, and a runtime system that dynamically enforces the policies. In contrast with previous work, we do not assume any modifications to the Android operating system, and implement Draco in the Chromium Android System WebView app to enable seamless deployment. Our evaluation of the the Draco runtime system shows that Draco incurs negligible overhead, which is in the order of microseconds.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Automated Generation of Event-Oriented Exploits in Android Hybrid AppsGuangliang Yang, Jeff Huang, Guofei GuNDSS 2018 · 被引用 79 次
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
- AWare: Preventing Abuse of Privacy-Sensitive Sensors via Operation BindingsGiuseppe Petracca, Ahmad Atamli-Reineh, Yuqiong Sun, Jens Grossklags 等USENIX Security 2017 · 被引用 35 次
- Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile ApplicationsGuangliang Yang, Jeff Huang, Guofei Gu, Abner MendozaS&P 2018 · 被引用 27 次
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo 等FSE 2020 · 被引用 22 次
它引用的顶会 Paper1
相关 Paper
- Cross-Boundary Mobile Tracking: Exploring Java-to-JavaScript Information Diffusion in WebViewsSohom Datta, Michalis Diamantaris, Ahsan Zafar, Junhua Su 等NDSS 2026 · 被引用 2 次
- ReACt: A Resource-centric Access Control System for Web-app Interactions on AndroidXin Zhang, Yifan ZhangWWW 2021 · 被引用 3 次
- Harness: Transparent and Lightweight Protection of Vehicle Control on Untrusted Android Automotive Operating SystemHaochen Gong, Siyu Hong, Shenyi Yang, Rui Chang 等USENIX Security 2025
- Beast in the Cage: A Fine-grained and Object-oriented Permission System to Confine JavaScript Operations on the WebRui ZhaoWWW 2025 · 被引用 2 次
- Tabbed Out: Subverting the Android Custom Tab Security ModelPhilipp Beer, Marco Squarcina, Lorenzo Veronese, Martina LindorferS&P 2024 · 被引用 7 次
