摘要
为了保护Android智能手机安全,在深入分析Android系统安全机制的基础上,提出了一个基于强制访问控制的安全加固技术。该技术首先通过修改Android内核,添加一个平台无关的强制访问框架,其次为进程、文件等系统对象添加安全属性,最后通过制定一套细粒度的强制访问规则,对应用程序实施强制访问控制。通过在模拟环境中的测试,验证了该技术可以有效保护Android系统安全。
To protect the Android-powered smartphones, a security reinforcement technology based on mandatory access control is proposed. It is implemented as follows: first, a platform-independent mandatory access control framework is added to the Android kernel; then, security attributes are attached to system objects; finally, a set of fine-grained access rules are made to control applications' permissions. The effectiveness of the technology is proved through the test in an emulator environment.
出处
《计算机系统应用》
2011年第10期74-77,共4页
Computer Systems & Applications