检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:刘子煜 吴健学[1] LIU Zi-yu;WU Jian-xue(Wuhan Research Institute of Posts and Telecommunications,Wuhan,Hubei 430074,China)
出 处:《计算技术与自动化》2018年第1期117-120,共4页Computing Technology and Automation
摘 要:随着移动互联网的发展,Android手机平台内越来越多的APP具有移动支付功能。移动支付涉及到金融交易,支付信息安全显得尤为重要。本文分析了Android的Binder机制,通过将监控代码动态注入目标模块,对进程间的通信数据进行提取,通过比对既有信息,分析是否有恶意软件窃取目标APP的用户隐私信息。在支付环节之前将检测结果对用户给予提示,且对支付过程无较大影响,一定程度上保障了用户支付信息的安全。With the development of mobile Internet,more and more applications include the function of mobile payment in Android mobile phone platform.Mobile payment involves financial transactions,information security of payment is more and more important.This article first analyzes Binder principle of Android system,and then by injecting the code into the target module,the communication data between the processes can be extracted.Second,by comparing the existing information,analysis of whether there is malicious software to steal the user s privacy information of target application.The result of the test is given to the users before the payment,and there is no significant impact on the payment process.This scheme guarantees the information security of payment in a certain extent.
关 键 词:ANDROID系统 BINDER 动态注入 信息提取
分 类 号:TN918.9[电子电信—通信与信息系统]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.222