首页> 外文期刊>IEEE transactions on information forensics and security >Rethinking Permission Enforcement Mechanism on Mobile Systems
【24h】

Rethinking Permission Enforcement Mechanism on Mobile Systems

机译:对移动系统上的权限执行机制的重新思考

获取原文
获取原文并翻译 | 示例
           

摘要

To protect sensitive resources from unauthorized use, modern mobile systems, such as Android and iOS, design a permission-based access control model. However, current model could not enforce fine-grained control over the dynamic permission use contexts, causing two severe security problems. First, any code package in an application could use the granted permissions, inducing attackers to embed malicious payloads into benign apps. Second, the permissions granted to a benign application may be utilized by an attacker through vulnerable application interactions. Although ad hoc solutions have been proposed, none could systematically solve these two issues within a unified framework. This paper presents the first such framework to provide context-sensitive permission enforcement that regulates permission use policies according to system-wide application contexts, which cover both intra-application context and inter-application context. We build a prototype system on Android, named FineDroid, to track such context during the application execution. To flexibly regulate the context-sensitive permission rules, FineDroid features a policy framework that could express generic application contexts. We demonstrate the benefits of FineDroid by instantiating several security extensions based on the policy framework, for three potential users: end users, administrators, and developers. Furthermore, FineDroid is showed to introduce a minor overhead.
机译:为了保护敏感资源免遭未经授权的使用,现代移动系统(例如Android和iOS)设计了基于权限的访问控制模型。但是,当前模型无法对动态权限使用上下文实施细粒度控制,从而导致两个严重的安全问题。首先,应用程序中的任何代码包都可以使用授予的权限,从而诱使攻击者将恶意有效载荷嵌入到良性应用程序中。其次,攻击者可以通过易受攻击的应用程序交互来利用授予良性应用程序的权限。尽管已经提出了临时解决方案,但是没有一个解决方案可以在统一框架内系统地解决这两个问题。本文提出了第一个提供上下文敏感的权限实施的框架,该框架根据系统范围的应用程序上下文(包括应用程序内部上下文和应用程序间上下文)来规范权限使用策略。我们在Android上构建了一个名为FineDroid的原型系统,以在应用程序执行期间跟踪此类上下文。为了灵活地调节上下文相关的权限规则,FineDroid提供了可以表达通用应用程序上下文的策略框架。通过为三个潜在用户(最终用户,管理员和开发人员)基于策略框架实例化几个安全扩展,我们展示了FineDroid的好处。此外,FineDroid被证明会引入较小的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号