[1] Android Open Source Project, "APK Signature Scheme v2/v3 and app signing", source.android.com/security/apksigning
[2] OWASP, "Mobile Top 10" (移动应用十大风险概述), owasp.org/www-project-mobile-top-10/
[3] Enck W., et al., "TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones," OSDI 2010.
[4] Felt A.P., et al., "A study of Android application permissions," 权威移动权限研究。
[5] McMahan B., et al., "Communication-Efficient Learning of Deep Networks from Decentralized Data," AISTATS 2017 (联邦学习基础性论文).
[6] Dwork C., Roth A., "The Algorithmic Foundations of Differential Privacy," 2014.
[7] NIST Special Publication 800-52 Rev. 2, "Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations," 2019.
[8] Google Play Protect & industry自动化检测实践说明(公开技术文档)。
评论
Ethan_Wang
很有深度的分析,关于签名校验和差分隐私部分尤其有启发。期待关于APK签名检查的实操清单。
小周
建议补充国内各大应用市场上架合规流程的细节,这对企业落地很有帮助。
TechReviewer88
对联邦学习的解释清晰,引用文献权威,文章结构严谨,值得收藏转载。
陈若
是否可以再出一版针对普通用户的快速自检指南,帮助非专业用户也能完成基础核验?