Suppr超能文献

剖析 Android 平台中的接触者追踪应用。

Dissecting contact tracing apps in the Android platform.

机构信息

Department of Information & Communication Systems Engineering, University of the Aegean, Karlovasi, Greece.

European Commission, Joint Research Centre (JRC), Karlovasi, Italy.

出版信息

PLoS One. 2021 May 14;16(5):e0251867. doi: 10.1371/journal.pone.0251867. eCollection 2021.

Abstract

Contact tracing has historically been used to retard the spread of infectious diseases, but if it is exercised by hand in large-scale, it is known to be a resource-intensive and quite deficient process. Nowadays, digital contact tracing has promptly emerged as an indispensable asset in the global fight against the coronavirus pandemic. The work at hand offers a meticulous study of all the official Android contact tracing apps deployed hitherto by European countries. Each app is closely scrutinized both statically and dynamically by means of dynamic instrumentation. Depending on the level of examination, static analysis results are grouped in two axes. The first encompasses permissions, API calls, and possible connections to external URLs, while the second concentrates on potential security weaknesses and vulnerabilities, including the use of trackers, in-depth manifest analysis, shared software analysis, and taint analysis. Dynamic analysis on the other hand collects data pertaining to Java classes and network traffic. The results demonstrate that while overall these apps are well-engineered, they are not free of weaknesses, vulnerabilities, and misconfigurations that may ultimately put the user security and privacy at risk.

摘要

接触者追踪在历史上曾被用于减缓传染病的传播,但如果在大规模情况下手动进行,已知这是一个资源密集型且相当不足的过程。如今,数字接触者追踪已迅速成为全球对抗冠状病毒大流行不可或缺的资产。目前的工作对迄今为止欧洲国家部署的所有官方 Android 接触者追踪应用程序进行了细致研究。每个应用程序都通过动态工具进行静态和动态的仔细检查。根据检查的级别,静态分析结果分为两个轴。第一个包括权限、API 调用和可能与外部 URL 的连接,而第二个则集中于潜在的安全弱点和漏洞,包括使用跟踪器、深入的清单分析、共享软件分析和污染分析。另一方面,动态分析收集与 Java 类和网络流量相关的数据。结果表明,虽然这些应用程序总体上设计良好,但它们并非没有弱点、漏洞和配置错误,这些最终可能会使用户的安全和隐私面临风险。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/490e/8121305/78e9956d0121/pone.0251867.g001.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验