首页> 外文期刊>Future generation computer systems >Automatic security verification of mobile app configurations
【24h】

Automatic security verification of mobile app configurations

机译:移动应用程序配置的自动安全验证

获取原文
获取原文并翻译 | 示例

摘要

AbstractThe swift and continuous evolution of mobile devices is encouraging both private and public organizations to adopt theBring Your Own Device(BYOD) paradigm. As a matter of fact, the BYOD paradigm drastically reduces costs and increases productivity by allowing employees to carry out business tasks on their personal devices. However, it also increases the security concerns, since a compromised device could disruptively access the resources of the organization. The current mobile application distribution model based on application markets does not cope with this issue. In a previous work the concept of secure meta-market has been introduced as a mean to distribute mobile applications always guaranteed to comply with any given BYOD policy. This is achieved through a suitable combination of static analysis (i.e. model checking) and code instrumentation techniques. Although crucial, enforcing security policies over individual applications is not sufficient in general. Indeed, several well documented threats arise from the malicious interaction among applications which are harmless if isolated. In this paper, a novel technique for the security verification of groups of mobile app is proposed. The approach relies on partial model checking (PMC) to extend the existing security guarantees to groups of applications. The experimental results demonstrate the viability of the approach. Moreover, we show through a case study that even a fairly simple security policy can be violated by applications which are compliant if considered one by one.HighlightsA practical approach to the validation of groups of mobile apps is presented.The approach relies on partial model checking for mitigating state explosion.Experiments on real applications show that the technique scales on real systems.The solution is integrated with a prototype of the Secure Meta-Market (SMM).
机译: 摘要 移动设备的迅捷和持续发展正在鼓励私人和公共组织采用自带设备< / ce:italic>(BYOD)范例。事实上,BYOD范式允许员工在自己的个人设备上执行业务任务,从而大大降低了成本并提高了生产率。但是,由于受感染的设备可能破坏性地访问组织的资源,因此这也增加了对安全性的担忧。当前基于应用程序市场的移动应用程序分发模型无法解决此问题。在先前的工作中,引入了安全元市场的概念,作为分发始终保证遵守任何给定BYOD策略的移动应用程序的手段。这是通过静态分析(即模型检查)和代码检测技术的适当组合来实现的。尽管至关重要,但通常对单个应用程序实施安全策略还不够。确实,一些经过充分记录的威胁来自应用程序之间的恶意交互,如果被隔离,它们是无害的。本文提出了一种新的用于移动应用程序群组安全性验证的技术。该方法依靠部分模型检查(PMC)将现有的安全保证扩展到应用程序组。实验结果证明了该方法的可行性。此外,我们通过一个案例研究表明,如果一个应用程序一个一个地考虑,那么即使是相当简单的安全策略也可能会被兼容的应用程序所违反。 突出显示 提供了一种验证移动应用程序组的实用方法。 该方法依靠部分模型检查来缓解状态爆炸。 Expe对真实应用程序的评估表明,该技术可以在实际系统上扩展。 该解决方案已与安全元市场(SMM)的原型集成。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号