首页> 外文学位 >Context-Dependent Privacy and Security Management on Mobile Devices
【24h】

Context-Dependent Privacy and Security Management on Mobile Devices

机译:移动设备上的上下文相关隐私和安全管理

获取原文
获取原文并翻译 | 示例

摘要

There are ongoing security and privacy concerns regarding mobile platforms that are being used by a growing number of citizens. Security and privacy models typically used by mobile platforms use one-time permission acquisition mechanisms. However, modifying access rights after initial authorization in mobile systems is often too tedious and complicated for users. User studies show that a typical user does not understand permissions requested by applications or are too eager to use the applications to care to understand the permission implications. For example, the Brightest Flashlight application was reported to have logged precise locations and unique user identifiers, which have nothing to do with a flashlight application's intended functionality, but more than 50 million users used a version of this application which would have forced them to allow this permission. Given the penetration of mobile devices into our lives, a fine-grained context-dependent security and privacy control approach needs to be created.;We have created Mithril as an end-to-end mobile access control framework that allows us to capture access control needs for specific users, by observing violations of known policies. The framework studies mobile application executables to better inform users of the risks associated with using certain applications. The policy capture process involves an iterative user feedback process that captures policy modifications required to mediate observed violations. Precision of policy is used to determine convergence of the policy capture process. Policy rules in the system are written using Semantic Web technologies and the Platys ontology to define a hierarchical notion of context. Policy rule antecedents are comprised of context elements derived using the Platys ontology employing a query engine, an inference mechanism and mobile sensors. We performed a user study that proves the feasibility of using our violation driven policy capture process to gather user-specific policy modifications.;We contribute to the static and dynamic study of mobile applications by defining "application behavior" as a possible way of understanding mobile applications and creating access control policies for them. Our user study also shows that unlike our behavior-based policy, a "deny by default" mechanism hampers usability of access control systems. We also show that inclusion of crowd-sourced policies leads to further reduction in user burden and need for engagement while capturing context-based access control policy. We enrich knowledge about mobile "application behavior" and expose this knowledge through the Mobipedia knowledge-base. We also extend context synthesis for semantic presence detection on mobile devices by combining Bluetooth, low energy beacons and Nearby Messaging services from Google.
机译:关于移动平台的安全和隐私问题一直存在,越来越多的人正在使用该移动平台。移动平台通常使用的安全性和隐私模型使用一次性权限获取机制。然而,对于用户而言,在移动系统中进行初始授权后修改访问权限通常过于繁琐和复杂。用户研究表明,典型用户不理解应用程序所请求的权限,或者过于渴望使用应用程序来了解权限的含义。例如,据报道,Brightest Flashlight应用程序已记录了精确的位置和唯一的用户标识符,这与Flashlight应用程序的预期功能无关,但是超过5000万用户使用了该应用程序的版本,这迫使他们允许此权限。鉴于移动设备已渗透到我们的生活中,因此需要创建一种细粒度的上下文相关的安全和隐私控制方法。;我们创建了Mithril作为端到端移动访问控制框架,使我们能够捕获访问控制通过观察违反已知策略的行为来满足特定用户的需求。该框架研究移动应用程序可执行文件,以更好地告知用户使用某些应用程序带来的风险。策略捕获过程涉及迭代的用户反馈过程,该过程捕获捕获调解观察到的违例所必需的策略修改。策略的精度用于确定策略捕获过程的收敛性。系统中的策略规则是使用语义Web技术和Platys本体编写的,用于定义上下文的分层概念。策略规则前提由使用查询引擎,推理机制和移动传感器的使用Platys本体派生的上下文元素组成。我们进行了一项用户研究,证明了使用违规驱动的策略捕获过程来收集特定于用户的策略修改的可行性。;我们通过定义“应用行为”作为理解移动的可能方式,为移动应用的静态和动态研究做出了贡献应用程序并为其创建访问控制策略。我们的用户研究还表明,与基于行为的策略不同,“默认情况下拒绝”机制会妨碍访问控制系统的可用性。我们还显示,包含众包策略可以进一步减轻用户负担,并在捕获基于上下文的访问控制策略时吸引用户参与。我们丰富了有关移动“应用程序行为”的知识,并通过Mobipedia知识库公开了这些知识。我们还结合了蓝牙,低能耗信标和Google的附近消息服务,将上下文综合扩展到移动设备上的语义存在检测。

著录项

  • 作者

    Das, Prajit Kumar.;

  • 作者单位

    University of Maryland, Baltimore County.;

  • 授予单位 University of Maryland, Baltimore County.;
  • 学科 Computer science.;Engineering.
  • 学位 Ph.D.
  • 年度 2017
  • 页码 147 p.
  • 总页数 147
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号