2017 IEEE 31st International Conference on Advanced Information Networking and Applications (AINA) 2017
DOI: 10.1109/aina.2017.61
|View full text |Cite
|
Sign up to set email alerts
|

Access Control for Plugins in Cordova-Based Hybrid Applications

Abstract: Hybrid application frameworks such as Cordova allow mobile application (app) developers to create platformindependent apps. The code is written in JavaScript, with special APIs to access device resources in a platform-agnostic way. In this paper, we present a novel app-repackaging attack that repackages hybrid apps with malicious code; this code can exploit Cordova's plugin interface to tamper with device resources. We further demonstrate a defense against this attack through the use of a novel runtime access … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2018
2018
2021
2021

Publication Types

Select...
3
2

Relationship

1
4

Authors

Journals

citations
Cited by 5 publications
(3 citation statements)
references
References 10 publications
(8 reference statements)
0
3
0
Order By: Relevance
“…The application created by Cordova is still packaged as an SDK application, and can be downloaded and installed easily. The cloud package app of Cordova is compatible with all the operating systems, including iOS, Android, Windows phone, Blackberry, and Symbian [15]. An application structure based upon the classical Cordova framework is shown in Fig.…”
Section: Technologies For Hybrid Platform Based Applicationsmentioning
confidence: 99%
“…The application created by Cordova is still packaged as an SDK application, and can be downloaded and installed easily. The cloud package app of Cordova is compatible with all the operating systems, including iOS, Android, Windows phone, Blackberry, and Symbian [15]. An application structure based upon the classical Cordova framework is shown in Fig.…”
Section: Technologies For Hybrid Platform Based Applicationsmentioning
confidence: 99%
“…Some countermeasures based on access control have been presented for the attacks exploiting WebView. In [12], the authors present an access control mechanism that restricts access to device resources based on the user's judgement for mitigating apprepackaging attacks and cross-site scripting attacks. In [6], the authors provide uniform and fine-grained access control for web code running on Android apps using WebView.…”
Section: Security Issuesmentioning
confidence: 99%
“…Hybrid application is a technology that allows a similar learning media can be used on various types of smart phones [6][7][8][9]. This work implements the hybrid application and implements fisher yates shuffle as the randomization algorithm and answer option in the exam and practice module.…”
Section: Introductionmentioning
confidence: 99%