{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T12:16:35Z","timestamp":1763468195624},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319083438"},{"type":"electronic","value":"9783319083445"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-08344-5_23","type":"book-chapter","created":{"date-parts":[[2014,7,4]],"date-time":"2014-07-04T10:38:15Z","timestamp":1404470295000},"page":"354-369","source":"Crossref","is-referenced-by-count":11,"title":["Once Root Always a Threat: Analyzing the Security Threats of Android Permission System"],"prefix":"10.1007","author":[{"given":"Zhongwen","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuewu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiwu","family":"Jing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiongxiao","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingguang","family":"Lei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"23_CR1","unstructured":"Alves, T., Felton, D.: Trustzone: Integrated hardware and software security. ARM White Paper 3(4) (2004)"},{"key":"23_CR2","doi-asserted-by":"crossref","unstructured":"Au, K.W.Y., Zhou, Y.F., Huang, Z., Lie, D.: Pscout: analyzing the android permission specification. In: ACM CCS (2012)","DOI":"10.1145\/2382196.2382222"},{"key":"23_CR3","unstructured":"Bugiel, S., Davi, L., Dmitrienko, A., Fischer, T., Sadeghi, A.R.: XMandroid: a new android evolution to mitigate privilege escalation attacks. Technische Universit\u00e4t Darmstadt, Technical Report TR-2011-04 (2011)"},{"key":"23_CR4","unstructured":"Bugiel, S., Davi, L., Dmitrienko, A., Fischer, T., Sadeghi, A.R., Shastry, B.: Towards taming privilege-escalation attacks on android. In: 19th NDSS (2012)"},{"key":"23_CR5","doi-asserted-by":"crossref","unstructured":"Chin, E., Felt, A.P., Greenwood, K., Wagner, D.: Analyzing inter-application communication in android. In: 9th MobiSys (2011)","DOI":"10.1145\/1999995.2000018"},{"key":"23_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"331","DOI":"10.1007\/978-3-642-18178-8_29","volume-title":"Information Security","author":"M. Conti","year":"2011","unstructured":"Conti, M., Nguyen, V.T.N., Crispo, B.: Crepe: Context-related policy enforcement for android. In: Burmester, M., Tsudik, G., Magliveras, S., Ili\u0107, I. (eds.) ISC 2010. LNCS, vol.\u00a06531, pp. 331\u2013345. Springer, Heidelberg (2011)"},{"key":"23_CR7","unstructured":"Davi, L., Dmitrienko, A., Egele, M., Fischer, T., Holz, T., Hund, R., N\u00fcrnberger, S., Sadeghi, A.R.: Mocfi: A framework to mitigate control-flow attacks on smartphones. In: NDSS (2012)"},{"key":"23_CR8","doi-asserted-by":"crossref","unstructured":"Dietrich, K., Winter, J.: Secure boot revisited. In: ICYCS (2008)","DOI":"10.1109\/ICYCS.2008.535"},{"key":"23_CR9","unstructured":"Dietz, M., Shekhar, S., Pisetsky, Y., Shu, A., Wallach, D.S.: Quire: Lightweight provenance for smart phone operating systems. In: USENIX Security (2011)"},{"key":"23_CR10","unstructured":"Duo Security: X-ray for Android (2012), \n                    \n                      http:\/\/www.xray.io\/"},{"key":"23_CR11","unstructured":"Ekberg, J.E.: Secure boot with trusted computing group platform registers, US Patent US20120297175 A1 (November 22, 2012)"},{"key":"23_CR12","unstructured":"Enck, W., Ongtang, M., McDaniel, P.: Mitigating android software misuse before it happens. Technical Report NAS-TR-0094-2008 (September 2008)"},{"key":"23_CR13","doi-asserted-by":"crossref","unstructured":"Enck, W., Ongtang, M., McDaniel, P.: On lightweight mobile phone application certification. In: 16th ACM CCS (2009)","DOI":"10.1145\/1653662.1653691"},{"key":"23_CR14","doi-asserted-by":"crossref","unstructured":"Felt, A.P., Chin, E., Hanna, S., Song, D., Wagner, D.: Android permissions demystified. In: 18th ACM CCS (2011)","DOI":"10.1145\/2046707.2046779"},{"key":"23_CR15","unstructured":"Felt, A.P., Wang, H.J., Moshchuk, A., Hanna, S., Chin, E.: Permission re-delegation: Attacks and defenses. In: USENIX Security Symposium (2011)"},{"key":"23_CR16","unstructured":"Fuchs, A.P., Chaudhuri, A., Foster, J.S.: Scandroid: Automated security certification of android applications. Univ. of Maryland (2009) (manuscript)"},{"key":"23_CR17","unstructured":"Grace, M., Zhou, Y., Wang, Z., Jiang, X.: Systematic detection of capability leaks in stock android smartphones. In: Proceedings of the 19th NDSS (2012)"},{"key":"23_CR18","doi-asserted-by":"crossref","unstructured":"Hornyack, P., Han, S., Jung, J., Schechter, S., Wetherall, D.: These aren\u2019t the droids you\u2019re looking for: retrofitting android to protect data from imperious applications. In: 18th ACM CCS (2011)","DOI":"10.1145\/2046707.2046780"},{"key":"23_CR19","doi-asserted-by":"crossref","unstructured":"Kai, T., Xin, X., Guo, C.: The secure boot of embedded system based on mobile trusted module. In: ISDEA (2012)","DOI":"10.1109\/ISdea.2012.646"},{"key":"23_CR20","unstructured":"LifeHacker: Top 10 reasons to root your android phone, \n                    \n                      http:\/\/lifehacker.com\/top-10-reasons-to-root-your-android-phone-1079161983"},{"key":"23_CR21","doi-asserted-by":"crossref","unstructured":"Nauman, M., Khan, S., Zhang, X.: Apex: extending android permission model and enforcement with user-defined runtime constraints. In: 5th ACM CCS (2010)","DOI":"10.1145\/1755688.1755732"},{"key":"23_CR22","unstructured":"NC State University: Security alert: New sophisticated android malware droidkungfu found in alternative chinese app markets (2011), \n                    \n                      http:\/\/www.csc.ncsu.edu\/faculty\/jiang\/DroidKungFu.html"},{"key":"23_CR23","unstructured":"NetQin: 2012 moblie phone security report (2012), \n                    \n                      http:\/\/cn.nq.com\/neirong\/2012shang.pdf"},{"key":"23_CR24","unstructured":"Nicolson, K.A.: Secure boot with optional components method, US Patent US20100318781 A1 (December 16, 2010)"},{"key":"23_CR25","doi-asserted-by":"crossref","unstructured":"Ongtang, M., McLaughlin, S., Enck, W., McDaniel, P.: Semantically rich application-centric security in android. In: SCN (2012)","DOI":"10.1002\/sec.360"},{"key":"23_CR26","unstructured":"Schlegel, R., Zhang, K., Zhou, X.Y., Intwala, M., Kapadia, A., Wang, X.: Soundcomber: A stealthy and context-aware sound trojan for smartphones. In: NDSS (2011)"},{"key":"23_CR27","unstructured":"Smalley, S., Craig, R.: Security Enhanced (SE) Android: Bringing Flexible MAC to Android. In: NDSS (2013)"},{"key":"23_CR28","unstructured":"Symantec: Android.basebridge (2011), \n                    \n                      http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2011-060915-4938-99"},{"key":"23_CR29","unstructured":"Toptenreviews: 2014 Best Mobile Security Software Comparisons and Reviews (2014), \n                    \n                      http:\/\/mobile-security-software-review.toptenreviews.com\/"},{"key":"23_CR30","unstructured":"Trusted Computing Group (TCG): Mobile Phone Work Group Mobile Trusted Module Specification (2010), \n                    \n                      http:\/\/www.trustedcomputinggroup.org\/developers\/mobile\/specifications"},{"key":"23_CR31","unstructured":"viaForensics: Defeating SEAndroid C DEFCON 21 Presentation, \n                    \n                      http:\/\/viaforensics.com\/mobile-security\/implementing-seandroid\/\/-defcon-21-presentation.html\n                    \n                    \n                   (March 8, 2013)"},{"key":"23_CR32","doi-asserted-by":"crossref","unstructured":"Winter, J.: Trusted computing building blocks for embedded linux-based arm trustzone platforms. In: 3rd ACM Workshop on Scalable Trusted Computing (2008)","DOI":"10.1145\/1456455.1456460"},{"key":"23_CR33","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Jiang, X.: Dissecting android malware: Characterization and evolution. In: Security and Privacy (SP), pp. 95\u2013109. IEEE (2012)","DOI":"10.1109\/SP.2012.16"},{"key":"23_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/978-3-642-21599-5_7","volume-title":"Trust and Trustworthy Computing","author":"Y. Zhou","year":"2011","unstructured":"Zhou, Y., Zhang, X., Jiang, X., Freeh, V.W.: Taming information-stealing smartphone applications (on android). In: McCune, J.M., Balacheff, B., Perrig, A., Sadeghi, A.-R., Sasse, A., Beres, Y. (eds.) Trust 2011. LNCS, vol.\u00a06740, pp. 93\u2013107. Springer, Heidelberg (2011)"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-08344-5_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,27]],"date-time":"2019-05-27T06:27:02Z","timestamp":1558938422000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-08344-5_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319083438","9783319083445"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-08344-5_23","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}