Full Program »
Scippa: System-Centric IPC Provenance on Android
We present an extension to the Android IPC mechanism, called Scippa, that establishes IPC call-chains across application processes. Scippa provides provenance information required to effectively prevent recent attacks such as confused deputy attacks. Our solution constitutes a system-centric approach that extends the Binder kernel module and Android's message handlers. Scippa integrates seamlessly into the system architecture and our evaluation shows a performance overhead of only 2.23% on Android OS v4.2.2.
Author(s):
Michael Backes
Saarland University and MPI-SWS
Germany
Sven Bugiel
Saarland University, CISPA
Germany
Sebastian Gerling
Saarland University, CISPA
Germany