{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:28:44Z","timestamp":1750307324109,"version":"3.41.0"},"reference-count":7,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2012,9,2]],"date-time":"2012-09-02T00:00:00Z","timestamp":1346544000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGSOFT Softw. Eng. Notes"],"published-print":{"date-parts":[[2012,9,7]]},"abstract":"<jats:p>The current Android application framework has an \"all or none\" permission policy, viz., an application can be installed if and only if all the permissions are granted. Also, no provision exists to deny granted permissions after installation. Therefore, any application can misuse the granted permission. CyanogenMod addresses this issue by denying the unwanted permissions which might cause the application to crash. WhisperCore, has worked on this problem but the working model is unavailable at the moment. APEX, also is currently doing some research on this issue but there is no publicly available document.<\/jats:p>\n          <jats:p>In this paper, the problem of misusing the granted permission n in Android is addressed and a novel idea of 'shadow manifest' is proposed. The proposed shadow manifest is implemented by creating a novel Content Provider, viz., SelPermProvider, which hosts the user permissions. In general, during the resource request phase, the system manifest is checked and the resources are allocated. But, in our implementation, the control is altered to flow through the shadow manifest after the system manifest is checked. If the query to shadow manifest is TRUE, then the resource is granted else a dummy or null value is returned. This facilitates the user to identify the malware and block the malware from achieving the intended task. Thus, the application is unaware of the indirect permission denial and continues to run normally. The user can decide which permission to restrict by checking a log of all recent permission requests, a facility provided in our app.<\/jats:p>\n          <jats:p>The proposed shadow manifest has been implemented and tested using an application called 'Contacts_Retrieve'. It was found to successfully complete the application if the shadow manifest returned TRUE, and unsuccessfully complete otherwise.<\/jats:p>","DOI":"10.1145\/2347696.2347711","type":"journal-article","created":{"date-parts":[[2012,9,11]],"date-time":"2012-09-11T22:21:06Z","timestamp":1347402066000},"page":"1-9","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Avoidance of security breach through selective permissions in android operating system"],"prefix":"10.1145","volume":"37","author":[{"given":"Lakshmi Priya","family":"Sekar","sequence":"first","affiliation":[{"name":"National Institute of Technology, Tiruchirappalli, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vinitha Reddy","family":"Gankidi","sequence":"additional","affiliation":[{"name":"National Institute of Technology, Tiruchirappalli, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Selvakumar","family":"Subramanian","sequence":"additional","affiliation":[{"name":"National Institute of Technology, Tiruchirappalli, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,9,2]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Android open source project Application Sandbox http:\/\/source.android.com\/tech\/security\/index.html.  Android open source project Application Sandbox http:\/\/source.android.com\/tech\/security\/index.html."},{"key":"e_1_2_1_2_1","unstructured":"Android open source project Elements of Applications Interprocess Communication http:\/\/source.android.com\/tech\/security\/index.html.  Android open source project Elements of Applications Interprocess Communication http:\/\/source.android.com\/tech\/security\/index.html."},{"key":"e_1_2_1_3_1","unstructured":"CyanogenMod Permission Management- CyanogenMod Settings http:\/\/www.cyanogenmod.com\/about.  CyanogenMod Permission Management- CyanogenMod Settings http:\/\/www.cyanogenmod.com\/about."},{"key":"e_1_2_1_4_1","unstructured":"WhisperSystems Selective permissions for Android http:\/\/www.whispersys.com\/permissions.html.  WhisperSystems Selective permissions for Android http:\/\/www.whispersys.com\/permissions.html."},{"issue":"4","key":"e_1_2_1_5_1","volume":"8","author":"Sohail Khan Design","year":"2011","unstructured":"Mohammad Nauman and Sohail Khan . Design and Implementation of a Fine-grained Resource Usage Model for the Android Platform. The International Arab Journal of Information Technology , Vol. 8 , No. 4 , Oct 2011 Mohammad Nauman and Sohail Khan. Design and Implementation of a Fine-grained Resource Usage Model for the Android Platform. The International Arab Journal of Information Technology, Vol.8, No.4, Oct 2011","journal-title":"Fine-grained Resource Usage Model for the Android Platform. The International Arab Journal of Information Technology"},{"key":"e_1_2_1_6_1","unstructured":"Stackoverflow Android \"Application Framework\" Docs\/Tuts http:\/\/stackoverflow.com\/questions\/8992677\/android-applicationframework-docs-tuts.  Stackoverflow Android \"Application Framework\" Docs\/Tuts http:\/\/stackoverflow.com\/questions\/8992677\/android-applicationframework-docs-tuts."},{"key":"e_1_2_1_7_1","unstructured":"GrepCode http:\/\/grepcode.com\/snapshot\/repository.grepcode.com\/java\/ext\/com.google.android\/android\/4.0.3_r1\/  GrepCode http:\/\/grepcode.com\/snapshot\/repository.grepcode.com\/java\/ext\/com.google.android\/android\/4.0.3_r1\/"}],"container-title":["ACM SIGSOFT Software Engineering Notes"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2347696.2347711","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2347696.2347711","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T11:05:58Z","timestamp":1750244758000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2347696.2347711"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,9,2]]},"references-count":7,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2012,9,7]]}},"alternative-id":["10.1145\/2347696.2347711"],"URL":"https:\/\/doi.org\/10.1145\/2347696.2347711","relation":{},"ISSN":["0163-5948"],"issn-type":[{"type":"print","value":"0163-5948"}],"subject":[],"published":{"date-parts":[[2012,9,2]]},"assertion":[{"value":"2012-09-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}