首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks >Don't Just BYOD, Bring-Your-Own-App Too! Protection via Virtual Micro Security Perimeters
【24h】

Don't Just BYOD, Bring-Your-Own-App Too! Protection via Virtual Micro Security Perimeters

机译:不要只是BYOD,您也要自己带来应用程序!通过虚拟微安全性边界进行保护

获取原文

摘要

Mobile devices are increasingly becoming a melting pot of different types of data ranging from sensitive corporate documents to commercial media to personal content produced and shared via online social networks. While it is desirable for such diverse content to be accessible from the same device via a unified user experience and through a rich plethora of mobile apps, ensuring that this data remains protected has become challenging. Even though different data types have very different security and privacy needs and accidental instances of data leakage are common, today's mobile operating systems include few, if any, facilities for fine-grained data protection and isolation. In this paper, we present SWIRLS, an Android-based mobile OS that provides a rich policy-based information-flow data protection abstraction for mobile apps to support BYOD (bring-your-own-device) use cases. SWIRLS allows security and privacy policies to be attached to individual pieces of data contained in signed and encrypted capsules, and enforces these policies as the data flows through the device. Unlike current BYOD solutions like VMs and containers that create duplication and cognitive overload, SWIRLS provides a single environment that allows users to access content belonging to different security contexts using the same applications without fear of inadverdant or malicious data leakage. SWIRLS also unburdens app developers from having to worry about security policies, and provides APIs through which they can create seamless multi-security-context user interfaces. To implement it's abstractions, SWIRLS develops a cryptographically protected capsule distribution and installation scheme, enhances Taintdroid-based taint-tracking mechanisms to support efficient kernel and user-space security policy enforcement, implements techniques for persisting security context along with data, and provides transparent security-context switching mechanisms. Using our Android-based prototype (>25K LOC), we show a number of data protection use-cases such as isolation of personal and work data, limiting document sharing and preventing leakage based on document classification, and security policies based on geo-and time-fencing. Our experiments show that SWIRLS imposes a very minimal overhead in both battery consumption and performance.
机译:移动设备正日益成为各种类型的数据的大熔炉,范围从敏感的公司文档到商业媒体再到通过在线社交网络生成和共享的个人内容。尽管希望通过统一的用户体验和大量的移动应用程序从同一设备访问此类多样化的内容,但是确保此数据受到保护已成为一项挑战。即使不同的数据类型具有非常不同的安全性和隐私需求,并且偶然发生数据泄漏的情况很普遍,但当今的移动操作系统几乎没有(如果有)用于细粒度数据保护和隔离的设施。在本文中,我们介绍了SWIRLS,这是一个基于Android的移动操作系统,可为移动应用程序提供丰富的基于策略的信息流数据保护抽象,以支持BYOD(自带设备)用例。 SWIRLS允许将安全和隐私策略附加到包含在经过签名和加密的数据包中的各个数据段,并在数据流经设备时强制执行这些策略。与当前的BYOD解决方案(如创建重复和认知过载的VM和容器)不同,SWIRLS提供了一个单一的环境,该环境使用户可以使用同一应用程序访问属于不同安全上下文的内容,而不必担心过分或恶意数据泄漏。 SWIRLS还减轻了应用程序开发人员不必担心安全策略的负担,并提供了API,通过它们可以创建无缝的多安全上下文用户界面。为了实现其抽象,SWIRLS开发了受密码保护的胶囊分配和安装方案,增强了基于Taintdroid的异味跟踪机制,以支持有效的内核和用户空间安全策略实施,实现了将安全性上下文与数据一起持久化的技术,并提供了透明的安全性-上下文切换机制。使用基于Android的原型(> 25K LOC),我们展示了许多数据保护用例,例如隔离个人数据和工作数据,限制文档共享并基于文档分类防止泄漏以及基于地理位置和安全性的安全策略。击剑。我们的实验表明,SWIRLS在电池消耗和性能方面的开销非常小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号