AUDACIOUS: User-Driven Access Control with Unmodified Operating Systems

被引:16
|
作者
Ringer, Talia [1 ]
Grossman, Dan [1 ]
Roesner, Franziska [1 ]
机构
[1] Univ Washington, Seattle, WA 98195 USA
关键词
D O I
10.1145/2976749.2978344
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
User-driven access control improves the coarse-grained access control of current operating systems (particularly in the mobile space) that provide only all-or-nothing access to a resource such as the camera or the current location. By granting appropriate permissions only in response to explicit user actions (for example, pressing a camera button), user driven access control better aligns application actions with user expectations. Prior work on user-driven access control has relied in essential ways on operating system (OS) modifications to provide applications with uncompromisable access control gadgets, distinguished user interface (UI) elements that can grant access permissions. This work presents a design, implementation, and evaluation of user-driven access control that works with no OS modifications, thus making deployability and incremental adoption of the model more feasible. We develop (1) a user level trusted library for access control gadgets, (2) static analyses to prevent malicious creation of UI events, illegal flows of sensitive information, and circumvention of our library, and (3) dynamic analyses to ensure users are not tricked into granting permissions. In addition to providing the original user-driven access control guarantees, we use static information flow to limit where results derived from sensitive sources may flow in an application. Our implementation targets Android applications. We port open-source applications that need interesting resource permissions to use our system. We determine in what ways user-driven access control in general and our implementation in particular are good matches for real applications. We demonstrate that our system is secure against a variety of attacks that malware on Android could otherwise mount.
引用
收藏
页码:204 / 216
页数:13
相关论文
共 50 条
  • [31] User-driven ontology evolution management
    Stojanovic, L
    Maedche, A
    Motik, B
    Stojanovic, N
    KNOWLEDGE ENGINEERING AND KNOWLEDGE MANAGEMENT, PROCEEDINGS: ONTOLOGIES AND THE SEMANTIC WEB, 2002, 2473 : 285 - 300
  • [32] User-Driven Services in District Heating
    Yli-Viitala, Pirjo
    Vanska, Juha
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON INNOVATION AND MANAGEMENT, VOLS I AND II, 2014, : 1362 - 1371
  • [33] Forte: User-Driven Generative Design
    Chen, Xiang 'Anthony'
    Tao, Ye
    Wang, Guanyun
    Kang, Runchang
    Grossman, Tovi
    Coros, Stelian
    Hudson, Scott E.
    PROCEEDINGS OF THE 2018 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS (CHI 2018), 2018,
  • [34] Evaluations of User-Driven Ontology Summarization
    Li, Ning
    Motta, Enrico
    KNOWLEDGE ENGINEERING AND MANAGEMENT BY THE MASSES, EKAW 2010, 2010, 6317 : 544 - 553
  • [35] User-Driven Refinement of Imprecise Queries
    Qarabaqi, Bahar
    2014 IEEE 30TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING WORKSHOPS (ICDEW), 2014, : 355 - 359
  • [36] USER-DRIVEN SEGMENTATION OF DESIGN DATA
    Maynard, Alex
    Burnap, Alexander
    Papalambros, Panos
    DS87-4 PROCEEDINGS OF THE 21ST INTERNATIONAL CONFERENCE ON ENGINEERING DESIGN (ICED 17), VOL 4: DESIGN METHODS AND TOOLS, 2017, : 473 - 482
  • [37] USER-DRIVEN SYSTEM AND A MODEST PROPOSAL
    MANN, D
    TEACHERS COLLEGE RECORD, 1978, 79 (03): : 389 - 412
  • [38] User-driven innovation of an outpatient department
    Broberg, Ole
    Edwards, Kasper
    WORK-A JOURNAL OF PREVENTION ASSESSMENT & REHABILITATION, 2012, 41 : 101 - 106
  • [39] Iterative User-Driven Fault Localization
    Li, Xiangyu
    d'Amorim, Marcelo
    Orso, Alessandro
    HARDWARE AND SOFTWARE: VERIFICATION AND TESTING, HVC 2016, 2016, 10028 : 82 - 98
  • [40] USER-DRIVEN HOUSING FOR OLDER PEOPLE
    Jonsson, O.
    Slaug, B.
    Haak, M.
    Oswald, F.
    Rimland, J. M.
    Tomsone, S.
    Svensson, T.
    Iwarsson, S.
    GERONTOLOGIST, 2015, 55 : 278 - 278