首页> 外文期刊>IEEE transactions on mobile computing >Construction and Mitigation of User-Behavior-Based Covert Channels on Smartphones
【24h】

Construction and Mitigation of User-Behavior-Based Covert Channels on Smartphones

机译:智能手机上基于用户行为的隐蔽通道的构建和缓解

获取原文
获取原文并翻译 | 示例

摘要

To protect user privacy, many smartphone systems adopt the permission-based mechanism in which a user can evaluate the risk of requests for private information from a mobile app before installing it. However, recent studies show that the permission based mechanism is vulnerable to application collusion attacks because two apps, which appear to be harmless individually, can establish a covert channel and use it to leak confidential information. Consequently, people have designed some covert channel detection schemes, by checking abnormal status of the phone. In this paper, we point out that existing covert channel detection schemes may fail to detect a new type of collusion attacks referred as user-behavior-based covert channels. We implement three covert channels on Android smartphones. Our work sets a new alarm for the security issue of using smartphones. We then study the countermeasures to this new type of covert channels. Instead of trying to directly detect the proposed new type of covert channels, we propose two mitigation solutions to reduce the effectiveness of such covert channels. The mitigation solutions are also valid to other existing sensor-based side channels and/or covert channels on the phone.
机译:为了保护用户隐私,许多智能手机系统采用基于权限的机制,用户可以在安装前评估来自移动应用程序的私人信息请求风险。但是,最近的研究表明,基于权限的机制很容易受到应用程序共谋攻击,因为两个看上去单独无害的应用程序可以建立秘密通道并使用它来泄漏机密信息。因此,人们通过检查手机的异常状态,设计了一些秘密通道检测方案。在本文中,我们指出现有的隐蔽通道检测方案可能无法检测到一种新型的共谋攻击,即基于用户行为的隐蔽通道。我们在Android智能手机上实现了三个秘密渠道。我们的工作为使用智能手机的安全性问题设置了新的警报。然后,我们研究针对这种新型隐蔽渠道的对策。与其尝试直接检测提议的新型隐蔽通道,不如提出两种缓解解决方案以降低此类隐蔽通道的有效性。缓解解决方案也适用于电话上其他现有的基于传感器的副信道和/或隐蔽信道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号