{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,22]],"date-time":"2026-03-22T14:34:16Z","timestamp":1774190056062,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":63,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642255595","type":"print"},{"value":"9783642255601","type":"electronic"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-25560-1_3","type":"book-chapter","created":{"date-parts":[[2011,11,9]],"date-time":"2011-11-09T22:28:46Z","timestamp":1320877726000},"page":"49-70","source":"Crossref","is-referenced-by-count":40,"title":["Defending Users against Smartphone Apps: Techniques and Future Directions"],"prefix":"10.1007","author":[{"given":"William","family":"Enck","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"3_CR1","unstructured":"AdMob: AdMob Android SDK: Installation Instructions, http:\/\/www.admob.com\/docs\/AdMob_Android_SDK_Instructions.pdf (accessed November 2010)"},{"key":"3_CR2","unstructured":"Android Market: March 2011 Security Issue (March 2011), https:\/\/market.android.com\/support\/bin\/answer.py?answer=1207928"},{"key":"3_CR3","unstructured":"Apple Inc.: Apple\u2019s App Store Downloads Top 10 Billion (January 2011), http:\/\/www.apple.com\/pr\/library\/2011\/01\/22appstore.html"},{"key":"3_CR4","doi-asserted-by":"crossref","unstructured":"Au, K., Zhou, B., Huang, Z., Gill, P., Lie, D.: Short Paper: A Look at SmartPhone Permission Models. In: Proceedings of the ACM Workshop on Security and Privacy in Mobile Devices, SPSM (2011)","DOI":"10.1145\/2046614.2046626"},{"key":"3_CR5","unstructured":"Barrera, D., Enck, W., van Oorschot, P.C.: Seeding a Security-Enhancing Infrastructure for Multi-market Application Ecosystems. Tech. Rep. TR-11-06, Carleton University, School of Computer Science, Ottawa, ON, Canada (April 2011)"},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"Barrera, D., Kayacik, H.G., van Oorshot, P.C., Somayaji, A.: A Methodology for Empirical Analysis of Permission-Based Security Models and its Application to Android. In: Proceedings of the ACM Conference on Computer and Communications Security (October 2010)","DOI":"10.1145\/1866307.1866317"},{"key":"3_CR7","unstructured":"Bell, D.E., LaPadula, L.J.: Secure Computer Systems: Mathematical Foundations. Tech. Rep. MTR-2547, Vol. 1, MITRE Corp., Bedford, MA (1973)"},{"key":"3_CR8","doi-asserted-by":"crossref","unstructured":"Beresford, A.R., Rice, A., Skehin, N., Sohan, R.: MockDroid: Trading Privacy for Application Functionality on Smartphones. In: Proceedings of the 12th Workshop on Mobile Computing Systems and Applications, HotMobile (2011)","DOI":"10.1145\/2184489.2184500"},{"key":"3_CR9","unstructured":"Biba, K.J.: Integrity considerations for secure computer systems. Tech. Rep. MTR-3153, MITRE (April 1977)"},{"key":"3_CR10","unstructured":"Bugiel, S., Davi, L., Dmitrienko, A., Fischer, T., Sadeghi, A.R.: XManDroid: A New Android Evolution to Mitigate Privilege Escalation Attacks. Tech. Rep. TR-2011-04, Technische Universitat Darmstadt, Center for Advanced Security Research Darmstadt, Darmstadt, Germany (April 2011)"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Bugiel, S., Davi, L., Dmitrienko, A., Heuser, S., Sadeghi, A.R., Shastry, B.: Practical and Lightweight Domain Isolation on Android. In: Proceedings of the ACM Workshop on Security and Privacy in Mobile Devices, SPSM (2011)","DOI":"10.1145\/2046614.2046624"},{"key":"3_CR12","doi-asserted-by":"crossref","unstructured":"Burguera, I., Zurutuza, U., Nadjm-Tehrani, S.: Crowdroid: Behavior-Based Malware Detection System for Android. In: Proceedings of the ACM Workshop on Security and Privacy in Mobile Devices, SPSM (2011)","DOI":"10.1145\/2046614.2046619"},{"key":"3_CR13","unstructured":"Burns, J.: Developing Secure Mobile Applications for Android. iSEC Partners (October 2008), http:\/\/www.isecpartners.com\/files\/iSEC_Securing_Android_Apps.pdf"},{"key":"3_CR14","unstructured":"Cannings, R.: Exercising Our Remote Application Removal Feature (June 2010), http:\/\/android-developers.blogspot.com\/2010\/06\/exercising-our-remote-application.html"},{"key":"3_CR15","doi-asserted-by":"crossref","unstructured":"Chaudhuri, A.: Language-Based Security on Android. In: Proceedings of the ACM SIGPLAN Workshop on Programming Languages and Analysis for Security (PLAS) (June 2009)","DOI":"10.1145\/1554339.1554341"},{"key":"3_CR16","doi-asserted-by":"crossref","unstructured":"Cheng, J., Wong, S.H., Yang, H., Lu, S.: SmartSiren: Virus Detection and Alert for Smartphones. In: Proceedings of the International Conference on Mobile Systems, Applications, and Services (MobiSys) (June 2007)","DOI":"10.1145\/1247660.1247690"},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Chin, E., Felt, A.P., Greenwood, K., Wagner, D.: Analyzing Inter-Application Communication in Android. In: Proceedings of the 9th Annual International Conference on Mobile Systems, Applications, and Services, MobiSys (2011)","DOI":"10.1145\/1999995.2000018"},{"key":"3_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"331","DOI":"10.1007\/978-3-642-18178-8_29","volume-title":"Information Security","author":"M. Conti","year":"2011","unstructured":"Conti, M., Nguyen, V.T.N., Crispo, B.: CRePE: Context-Related Policy Enforcement for Android. In: Burmester, M., Tsudik, G., Magliveras, S., Ili\u0107, I. (eds.) ISC 2010. LNCS, vol.\u00a06531, pp. 331\u2013345. Springer, Heidelberg (2011)"},{"issue":"4","key":"3_CR19","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1109\/MPRV.2004.21","volume":"3","author":"D. Dagon","year":"2004","unstructured":"Dagon, D., Martin, T., Starner, T.: Mobile Phones as Computing Devices: The Viruses are Coming! IEEE Pervasive Computing\u00a03(4), 11\u201315 (2004)","journal-title":"IEEE Pervasive Computing"},{"key":"3_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"346","DOI":"10.1007\/978-3-642-18178-8_30","volume-title":"Information Security","author":"L. Davi","year":"2011","unstructured":"Davi, L., Dmitrienko, A., Sadeghi, A.-R., Winandy, M.: Privilege Escalation Attacks on Android. In: Burmester, M., Tsudik, G., Magliveras, S., Ili\u0107, I. (eds.) ISC 2010. LNCS, vol.\u00a06531, pp. 346\u2013360. Springer, Heidelberg (2011)"},{"key":"3_CR21","doi-asserted-by":"crossref","unstructured":"Desmet, L., Joosen, W., Massacci, F., Philippaerts, P., Piessens, F., Siahaan, I., Vanoverberghe, D.: Security-by-contract on the. NET platform. Information Security Technical Report 13(1), 25\u201332 (2008)","DOI":"10.1016\/j.istr.2008.02.001"},{"key":"3_CR22","unstructured":"Dietz, M., Shekhar, S., Pisetsky, Y., Shu, A., Wallach, D.S.: Quire: Lightweight Provenance for Smart Phone Operating Systems. In: Proceedings of the 20th USENIX Security Symposium (August 2011)"},{"key":"3_CR23","unstructured":"Egele, M., Kruegel, C., Kirda, E., Vigna, G.: PiOS: Detecting Privacy Leaks in iOS Applications. In: Proceedings of the ISOC Network and Distributed System Security Symposium (NDSS) (February 2011)"},{"key":"3_CR24","unstructured":"Enck, W., Gilbert, P., Chun, B.G., Cox, L.P., Jung, J., McDaniel, P., Sheth, A.N.: TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones. In: Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI) (October 2010)"},{"key":"3_CR25","unstructured":"Enck, W., Octeau, D., McDaniel, P., Chaudhuri, S.: A Study of Android Application Security. In: Proceedings of the 20th USENIX Security Symposium (August 2011)"},{"key":"3_CR26","unstructured":"Enck, W., Ongtang, M., McDaniel, P.: Mitigating Android Software Misuse Before It Happens. Tech. Rep. NAS-TR-0094-2008, Network and Security Research Center, Department of Computer Science and Engineering, Pennsylvania State University, University Park, PA, USA (September 2008)"},{"key":"3_CR27","doi-asserted-by":"crossref","unstructured":"Enck, W., Ongtang, M., McDaniel, P.: On Lightweight Mobile Phone Application Certification. In: Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS) (November 2009)","DOI":"10.1145\/1653662.1653691"},{"issue":"1","key":"3_CR28","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MSP.2009.26","volume":"7","author":"W. Enck","year":"2009","unstructured":"Enck, W., Ongtang, M., McDaniel, P.: Understanding Android Security. IEEE Security & Privacy Magazine\u00a07(1), 50\u201357 (2009)","journal-title":"IEEE Security & Privacy Magazine"},{"key":"3_CR29","doi-asserted-by":"crossref","unstructured":"Felt, A.P., Chin, E., Hanna, S., Song, D., Wagner, D.: Android Permissions Demystified. In: Proceedings of the ACM Conference on Computer and Communications Security, CCS (2011)","DOI":"10.1145\/2046707.2046779"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Felt, A.P., Finifter, M., Chin, E., Hanna, S., Wagner, D.: A Survey of Mobile Malware in the Wild. In: Proceedings of the ACM Workshop on Security and Privacy in Mobile Devices, SPSM (2011)","DOI":"10.1145\/2046614.2046618"},{"key":"3_CR31","unstructured":"Felt, A.P., Greenwood, K., Wagner, D.: The Effectiveness of Application Permissions. In: Proceedings of the USENIX Conference on Web Application Development, WebApps (2011)"},{"key":"3_CR32","unstructured":"Felt, A.P., Wang, H.J., Moshchuk, A., Hanna, S., Chin, E.: Permission Re-Delegation: Attacks and Defenses. In: Proceedings of the 20th USENIX Security Symposium (August 2011)"},{"key":"3_CR33","unstructured":"Fuchs, A.P., Chaudhuri, A., Foster, J.S.: ScanDroid: Automated Security Certification of Android Applications, http:\/\/www.cs.umd.edu\/~avik\/projects\/scandroidascaa\/paper.pdf (accessed January 11, 2011)"},{"key":"#cr-split#-3_CR34.1","unstructured":"30. Gartner: Gartner Says Sales of Mobile Devices in Second Quarter of 2011 Grew 16.5 Percent Year-on-Year"},{"key":"#cr-split#-3_CR34.2","unstructured":"31. Smartphone Sales Grew 74 Percent (August 2011), http:\/\/www.gartner.com\/it\/page.jsp?id=1764714"},{"key":"3_CR35","doi-asserted-by":"crossref","unstructured":"Gilbert, P., Chun, B.G., Cox, L.P., Jung, J.: Vision: Automated Security Validation of Mobile Apps at App Markets. In: Proceedings of the International Workshop on Mobile Cloud Computing and Services, MCS (2011)","DOI":"10.1145\/1999732.1999740"},{"key":"3_CR36","doi-asserted-by":"crossref","unstructured":"Gudeth, K., Pirretti, M., Hoeper, K., Buskey, R.: Short Paper: Delivering Secure Applications on Commercial Mobile Devices: The Case for Bare Metal Hypervisors. In: Proceedings of the ACM Workshop on Security and Privacy in Mobile Devices, SPSM (2011)","DOI":"10.1145\/2046614.2046622"},{"key":"3_CR37","unstructured":"Guo, C., Wang, H.J., Zhu, W.: Smart-Phone Attacks and Defenses. In: Proceedings of the 3rd Workshop on Hot Topics in Networks, HotNets (2004)"},{"key":"3_CR38","doi-asserted-by":"crossref","unstructured":"Hornyack, P., Han, S., Jung, J., Schechter, S., Wetherall, D.: These Aren\u2019t the Droids You\u2019re Looking For: Retrofitting Android to Protect Data from Imperious Applications. In: Proceedings of the ACM Conference on Computer and Communications Security, CCS (2011)","DOI":"10.1145\/2046707.2046780"},{"key":"3_CR39","doi-asserted-by":"crossref","unstructured":"Ion, I., Dragovic, B., Crispo, B.: Extending the Java Virtual Machine to Enforce Fine-Grained Security Policies in Mobile Devices. In: Proceedings of the Annual Computer Security Applications Conference (ACSAC) (December 2007)","DOI":"10.1109\/ACSAC.2007.36"},{"key":"3_CR40","doi-asserted-by":"crossref","unstructured":"Karlson, A.K., Brush, A.B., Schechter, S.: Can I Borrow Your Phone? Understanding Concerns When Sharing Mobile Phones. In: Proceedings of the Conference on Human Factors in Computing Systems (CHI) (April 2009)","DOI":"10.1145\/1518701.1518953"},{"key":"3_CR41","doi-asserted-by":"crossref","unstructured":"Lange, M., Liebergeld, S., Lackorzynski, A., Warg, A., Peter, M.: L4Android: A Generic Operating System Framework for Secure Smartphones. In: Proceedings of the ACM Workshop on Security and Privacy in Mobile Devices, SPSM (2011)","DOI":"10.1145\/2046614.2046623"},{"key":"3_CR42","doi-asserted-by":"crossref","unstructured":"Liu, Y., Rahmati, A., Huang, Y., Jang, H., Zhong, L., Zhang, Y., Zhang, S.: xShare: Supporting Impromptu Sharing of Mobile Phones. In: Proceedings of the International Conference on Mobile Systems, Applications, and Services (MobiSys) (June 2009)","DOI":"10.1145\/1555816.1555819"},{"issue":"5","key":"3_CR43","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MSP.2010.159","volume":"8","author":"P. McDaniel","year":"2010","unstructured":"McDaniel, P., Enck, W.: Not So Great Expectations: Why Application Markets Haven\u2019t Failed Security. IEEE Security & Privacy Magazine\u00a08(5), 76\u201378 (2010)","journal-title":"IEEE Security & Privacy Magazine"},{"key":"3_CR44","doi-asserted-by":"crossref","unstructured":"Miettinen, M., Halonen, P., Hatonen, K.: Host-Based Intrusion Detection for Advanced Mobile Devices. In: Proceedings of the 20th International Conference on Advanced Information Networking and Applications (AINA) (April 2006)","DOI":"10.1109\/AINA.2006.192"},{"key":"3_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1007\/11790754_6","volume-title":"Detection of Intrusions and Malware & Vulnerability Assessment","author":"C. Mulliner","year":"2006","unstructured":"Mulliner, C., Vigna, G., Dagon, D., Lee, W.: Using Labeling to Prevent Cross-Service Attacks Against Smart Phones. In: B\u00fcschkes, R., Laskov, P. (eds.) DIMVA 2006. LNCS, vol.\u00a04064, pp. 91\u2013108. Springer, Heidelberg (2006)"},{"key":"3_CR46","doi-asserted-by":"crossref","unstructured":"Muthukumaran, D., Sawani, A., Schiffman, J., Jung, B.M., Jaeger, T.: Measuring Integrity on Mobile Phone Systems. In: Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), pp. 155\u2013164 (June 2008)","DOI":"10.1145\/1377836.1377862"},{"key":"3_CR47","doi-asserted-by":"crossref","unstructured":"Nauman, M., Khan, S., Zhang, X.: Apex: Extending Android Permission Model and Enforcement with User-defined Runtime Constraints. In: Proceedings of ASIACCS (2010)","DOI":"10.1145\/1755688.1755732"},{"key":"3_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-13869-0_1","volume-title":"Trust and Trustworthy Computing","author":"M. Nauman","year":"2010","unstructured":"Nauman, M., Khan, S., Zhang, X., Seifert, J.-P.: Beyond Kernel-Level Integrity Measurement: Enabling Remote Attestation for the Android Platform. In: Acquisti, A., Smith, S.W., Sadeghi, A.-R. (eds.) TRUST 2010. LNCS, vol.\u00a06101, pp. 1\u201315. Springer, Heidelberg (2010)"},{"key":"3_CR49","unstructured":"Ni, X., Yang, Z., Bai, X., Champion, A.C., Xuan, D.: DiffUser: Differentiated User Access Control on Smartphones. In: Proceedings of the 5th IEEE Workshop on Wireless and Sensor Networks Security (WSNS) (October 2009)"},{"key":"3_CR50","doi-asserted-by":"crossref","unstructured":"Oberheide, J., Veeraraghavan, K., Cooke, E., Flinn, J., Jahanian, F.: Virtualized In-Cloud Security Services for Mobile Devices. In: Proceedings of the 1st Workshop on Virtualization in Mobile Computing (June 2008)","DOI":"10.1145\/1622103.1629656"},{"key":"3_CR51","doi-asserted-by":"crossref","unstructured":"Ongtang, M., Butler, K., McDaniel, P.: Porscha: Policy Oriented Secure Content Handling in Android. In: Proceedings of the 26th Annual Computer Security Applications Conference (ACSAC) (December 2010)","DOI":"10.1145\/1920261.1920295"},{"key":"3_CR52","doi-asserted-by":"crossref","unstructured":"Ongtang, M., McLaughlin, S., Enck, W., McDaniel, P.: Semantically Rich Application-Centric Security in Android. In: Proceedings of the 25th Annual Computer Security Applications Conference (ACSAC), pp. 340\u2013349 (December 2009)","DOI":"10.1109\/ACSAC.2009.39"},{"key":"3_CR53","doi-asserted-by":"crossref","unstructured":"Ongtang, M., McLaughlin, S., Enck, W., McDaniel, P.: Semantically Rich Application-Centric Security in Android. Journal of Security and Communication Networks (2011), (Published online August 2011)","DOI":"10.1002\/sec.360"},{"key":"3_CR54","doi-asserted-by":"crossref","unstructured":"Portokalidis, G., Homburg, P., Anagnostakis, K., Bos, H.: Paranoid Android: Versatile Protection For Smartphones. In: Proceedings of the 26th Annual Computer Security Applications Conference (ACSAC) (December 2010)","DOI":"10.1145\/1920261.1920313"},{"key":"3_CR55","doi-asserted-by":"crossref","unstructured":"Schmidt, A.D., Peters, F., Lamour, F., Albayrak, S.: Monitoring Smartphones for Anomaly Detection. In: Proceedings of the 1st International Conference on MOBILe Wireless MiddleWARE, Operating Systems, and Applications, MOBILWARE (2008)","DOI":"10.4108\/ICST.MOBILWARE2008.2492"},{"key":"3_CR56","doi-asserted-by":"crossref","unstructured":"Schmidt, A.D., Schmidt, H.G., Batyuk, L., Clausen, J.H., Camtepe, S.A., Albayrak, S.: Smartphone Malware Evolution Revisited: Android Next Target? In: Proceedings of the 4th International Conference on Malicious and Unwanted Software (MALWARE) (October 2009)","DOI":"10.1109\/MALWARE.2009.5403026"},{"key":"3_CR57","doi-asserted-by":"crossref","unstructured":"Shabtai, A., Fledel, Y., Elovici, Y.: Securing Android-Powered Mobile Devices Using SELinux. IEEE Security and Privacy Magazine (May\/June 2010)","DOI":"10.1109\/MSP.2009.144"},{"key":"3_CR58","doi-asserted-by":"crossref","unstructured":"Shabtai, A., Kanonov, U., Elovici, Y., Glezer, C., Weiss, Y.: \u201cAndromaly\u201d: A Behavioral Malware Detection Framework for Android Devices. Journal of Intelligent Information Systems (2011), (published online January 2011)","DOI":"10.1007\/s10844-010-0148-x"},{"key":"3_CR59","unstructured":"VMware, Inc.: VMware Mobile Virtualization Platform, http:\/\/www.vmware.com\/products\/mobile\/ (accessed January 2011)"},{"key":"3_CR60","doi-asserted-by":"crossref","unstructured":"Zhang, X., Acii\u00e7mez, O., Seifert, J.P.: A Trusted Mobile Phone Reference Architecture via Secure Kernel. In: Proceedings of the ACM workshop on Scalable Trusted Computing, pp. 7\u201314 (November 2007)","DOI":"10.1145\/1314354.1314359"},{"key":"3_CR61","series-title":"LNICST","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/978-3-642-04434-2_7","volume-title":"Security and Privacy in Mobile Information and Communication Systems","author":"X. Zhang","year":"2009","unstructured":"Zhang, X., Ac\u0131i\u00e7mez, O., Seifert, J.-P.: Building efficient integrity measurement and Attestation for Mobile Phone Platforms. In: Schmidt, A.U., Lian, S. (eds.) MobiSec 2009. LNICST, vol.\u00a017, pp. 71\u201382. Springer, Heidelberg (2009)"},{"key":"3_CR62","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/978-3-642-21599-5_7","volume-title":"Trust and Trustworthy Computing","author":"Y. Zhou","year":"2011","unstructured":"Zhou, Y., Zhang, X., Jiang, X., Freeh, V.W.: Taming Information-Stealing Smartphone Applications (on Android). In: McCune, J.M., Balacheff, B., Perrig, A., Sadeghi, A.-R., Sasse, A., Beres, Y. (eds.) Trust 2011. LNCS, vol.\u00a06740, pp. 93\u2013107. Springer, Heidelberg (2011)"}],"container-title":["Lecture Notes in Computer Science","Information Systems Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-25560-1_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,19]],"date-time":"2019-06-19T05:59:29Z","timestamp":1560923969000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-25560-1_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642255595","9783642255601"],"references-count":63,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-25560-1_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011]]}}}