Custom permission is an important security feature of Android system. Permission resource app defines the custom permission. Resource provider app can share the app resources with the resource consumer apps which have gained the custom permission. However, evil app may potentially make permission squatting attacks, get ahead of legitimate permission source app to define the custom permission. If permission squatting attack is successful, then evil app can gain the access to the resource shared by resource provider app, and finally lead to security vulnerabilities and user data leakage. In this paper, we propose a scheme to provide permission source validation for the resource provider apps, which can enhance the calling context security for android custom permission, resistant to permission squatting attack, and suitable for app's self-protection.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.