A Distributed Android Security Framework

被引:1
|
作者
Andow, Benjamin [1 ]
Wang, Haodong [2 ]
机构
[1] North Carolina State Univ, Dept Comp Sci, Raleigh, NC 27695 USA
[2] Cleveland State Univ, Dept Elect Engn & Comp Sci, Cleveland, OH 44115 USA
关键词
D O I
10.1109/SmartCity.2015.207
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The current security models on mobile devices do not provide the level of protection required to handle sensitive data, such as protected healthcare information. In this paper, we introduce a Distributed Android Security Framework (DASF). DASF is a custom security framework for Android-based mobile devices that allows the enforcement of dynamic security policies on an application's privileges and sensitive data. DASF allows servers to dynamically impose security policies by using an application-layer message protocol implemented in the system. The security policies enforced by DASF enables system-wide privilege restrictions on untrustworthy applications and sensitive data. Ultimately, DASF allows organizations (i.e., data owners) to dynamically dictate the security policies enforced by the system, and retain control of the sensitive data they send to the device. We implement a prototype of DASF on Android Jellybean, and perform a security and performance evaluation. We show the DASF can defeat a number of security threats associated with using mobile devices in the healthcare industry, and imposes a reasonable performance overhead.
引用
收藏
页码:1045 / 1052
页数:8
相关论文
共 50 条
  • [1] An Empirical Evaluation of the Android Security Framework
    Armando, Alessandro
    Merlo, Alessio
    Verderame, Luca
    [J]. SECURITY AND PRIVACY PROTECTION IN INFORMATION PROCESSING SYSTEMS, 2013, 405 : 176 - 189
  • [2] An Android runtime security policy enforcement framework
    Banuri, Hammad
    Alam, Masoom
    Khan, Shahryar
    Manzoor, Jawad
    Ali, Bahar
    Khan, Yasar
    Yaseen, Mohsin
    Tahir, Mir Nauman
    Ali, Tamleek
    Alam, Quratulain
    Zhang, Xinwen
    [J]. PERSONAL AND UBIQUITOUS COMPUTING, 2012, 16 (06) : 631 - 641
  • [3] A Privacy Enhanced Security Framework for Android Users
    Singh, Shirish Kumar
    Mishra, Bharavi
    Gera, Poonam
    [J]. 2015 5TH INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2015,
  • [4] An Android runtime security policy enforcement framework
    Hammad Banuri
    Masoom Alam
    Shahryar Khan
    Jawad Manzoor
    Bahar Ali
    Yasar Khan
    Mohsin Yaseen
    Mir Nauman Tahir
    Tamleek Ali
    Quratulain Alam
    Xinwen Zhang
    [J]. Personal and Ubiquitous Computing, 2012, 16 : 631 - 641
  • [5] An Android runtime security policy enforcement framework
    Security Engineering Research Group , Institute of Management Sciences, 1-A, E-5, Phase VII, Hayatabad, Peshawar, Pakistan
    不详
    [J]. Pers. Ubiquitous Comp., 6 (631-641):
  • [6] A security framework for mHealth apps on Android platform
    Hussain, Muzammil
    Al-Haiqi, Ahmed
    Zaidan, A. A.
    Zaidan, B. B.
    Kiah, M.
    Iqbal, Salman
    Iqbal, S.
    Abdulnabi, Mohamed
    [J]. COMPUTERS & SECURITY, 2018, 75 : 191 - 217
  • [7] Context-Aware Security Framework for Android
    Tudorica, Contantin-Alexandru
    Gheorghe, Laura
    [J]. 2016 INTERNATIONAL WORKSHOP ON SECURE INTERNET OF THINGS (SIOT), 2016, : 11 - 19
  • [8] A Security Framework for Distributed Ledgers
    Graf, Mike
    Rausch, Daniel
    Ronge, Viktoria
    Egger, Christoph
    Kuesters, Ralf
    Schroeder, Dominique
    [J]. CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 1043 - 1064
  • [9] Formal Modeling and Reasoning about the Android Security Framework
    Armando, Alessandro
    Costa, Gabriele
    Merlo, Alessio
    [J]. TRUSTWORTHY GLOBAL COMPUTING, TGC 2013, 2013, 8358 : 64 - 81
  • [10] An enhanced security framework for reliable Android operating system
    Park, Jong Hyuk
    Kim, Dohyun
    Park, Ji Soo
    Lee, Sangjin
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (06) : 528 - 534