【24h】

Flexible Data-Driven Security for Android

机译:适用于Android的灵活的数据驱动的安全性

获取原文
获取原文并翻译 | 示例

摘要

Android allows users to cancel the installation of apps whenever requested permissions to resources seem inappropriate from their point of view. Since permissions can neither be granted individually nor changed after installation, this results in rather coarse, and often too liberal, access rules. We propose a more fine-grained security system beyond the standard permission system. With our system, it is possible to enforce complex policies that are built on temporal, cardinality, and spatial conditions ("notify if data is used after thirty days'''', "blur data outside company''s premises'''', etc.). Enforcement can be done by means of modification or inhibition of certain events and the execution of additional actions. Leveraging recent advances in information flow tracking technology, our policies can also pertain to data rather than single representations of that data. For instance, we can prohibit a movie from being played more than twice even if several copies have been created. We present design and implementation of the system and provide a security and performance analysis.
机译:从他们的角度来看,Android允许用户在请求的资源权限不合适时取消应用程序的安装。由于既不能单独授予权限,也不能在安装后更改权限,所以这会导致访问规则相当粗糙,并且通常过于宽松。我们提出了一种超越标准权限系统的更细粒度的安全系统。使用我们的系统,可以实施基于时间,基数和空间条件构建的复杂策略(“通知是否在30天后使用数据”,“在公司办公场所外模糊数据”''等)。可以通过修改或禁止某些事件以及执行其他操作来执行。利用信息流跟踪技术的最新进展,我们的策略也可以适用于数据,而不是数据的单一表示。例如,即使创建了多个副本,我们也可以禁止电影播放两次以上。我们介绍系统的设计和实现,并提供安全性和性能分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号