首页> 外文会议>International symposium on research in attacks, intrusion, and defenses >Practical Context-Aware Permission Control for Hybrid Mobile Applications
【24h】

Practical Context-Aware Permission Control for Hybrid Mobile Applications

机译:混合移动应用程序的实用上下文感知权限控制

获取原文

摘要

The rapid growth of mobile computing has resulted in the development of new programming paradigms for quick and easy development of mobile applications. Hybrid frameworks, such as PhoneGap, allow the use of web technologies for development of applications with native access to device's resources. These untrusted third-party applications desire access to user's data and device's resources, leaving the content vulnerable to accidental or malicious leaks by the applications. The hybrid frameworks present new opportunities to enhance the security of mobile platforms by providing an application-layer runtime for controlling an application's behavior. In this work, we present a practical design of a novel framework, named MobileIFC, for building privacy-preserving hybrid applications for mobile platforms. We use information flow models to control what untrusted applications can do with the information they receive. We utilize the framework to develop a fine-grained, context-sensitive permission model that enables users and application developers to specify rich policies. We show the viability of our design by means of a framework prototype. The usability of the framework and the permission model is further evaluated by developing sample applications using the framework APIs. Our evaluation and experience suggests that MobilelFC provides a practical and performant security solution for hybrid mobile applications.
机译:移动计算的迅速发展导致了新的编程范例的发展,以快速,轻松地开发移动应用程序。诸如PhoneGap之类的混合框架允许使用Web技术来开发对设备资源具有本地访问权限的应用程序。这些不受信任的第三方应用程序希望访问用户的数据和设备的资源,从而使内容容易受到应用程序意外或恶意泄漏的攻击。混合框架通过提供用于控制应用程序行为的应用程序层运行时,为增强移动平台的安全性提供了新的机会。在这项工作中,我们提出了一个名为MobileIFC的新颖框架的实用设计,该框架用于为移动平台构建保留隐私的混合应用程序。我们使用信息流模型来控制不受信任的应用程序可以如何使用它们接收的信息。我们利用该框架开发了一个细粒度的,上下文敏感的权限模型,该模型使用户和应用程序开发人员可以指定丰富的策略。我们通过框架原型展示了我们设计的可行性。通过使用框架API开发示例应用程序,可以进一步评估框架和权限模型的可用性。我们的评估和经验表明,MobilelFC为混合移动应用程序提供了实用且高性能的安全解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号