SPE: Security and Privacy Enhancement Framework for Mobile Devices

被引:13
|
作者
Krupp, Brian [1 ]
Sridhar, Nigamanth [2 ]
Zhao, Wenbing [2 ]
机构
[1] Baldwin Wallace Univ, Comp Sci Dept, Berea, OH 44145 USA
[2] Cleveland State Univ, Dept Elect Engn & Comp Sci, Cleveland, OH USA
基金
美国国家科学基金会;
关键词
Mobile security; mobile privacy; sensing; encryption; iOS; android;
D O I
10.1109/TDSC.2015.2465965
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present a security and privacy enhancement (SPE) framework for unmodified mobile operating systems. SPE introduces a new layer between the application and the operating system and does not require a device be jailbroken or utilize a custom operating system. We utilize an existing ontology designed for enforcing security and privacy policies on mobile devices to build a policy that is customizable. Based on this policy, SPE provides enhancements to native controls that currently exist on the platform for privacy and security sensitive components. SPE allows access to these components in a way that allows the framework to ensure the application is truthful in its declared intent and ensure that the user's policy is enforced. In our evaluation we verify the correctness of the framework and the computing impact on the device. Additionally, we discovered security and privacy issues in several open source applications by utilizing the SPE Framework. From our findings, if SPE is adopted by mobile operating systems producers, it would provide consumers and businesses the additional privacy and security controls they demand and allow users to be more aware of security and privacy issues with applications on their devices.
引用
收藏
页码:433 / 446
页数:14
相关论文
共 50 条
  • [1] The Security and Privacy Protection Framework for Wearable Devices
    Cui, Youxiang
    Gu, Zhongwei
    Sun, Lei
    Tang, Haibo
    Cui, Lumeng
    [J]. DESIGN, OPERATION AND EVALUATION OF MOBILE COMMUNICATIONS, MOBILE 2022, 2022, 13337 : 203 - 210
  • [2] A Security Monitoring Framework for Mobile Devices
    Lima, Antonio
    Rosa, Luis
    Cruz, Tiago
    Simoes, Paulo
    [J]. ELECTRONICS, 2020, 9 (08) : 1 - 25
  • [3] SECURITY AND PRIVACY IN AN ENTERPRISE SEARCH INFRASTRUCTURE FOR MOBILE DEVICES
    Praher, Christian P.
    Praher, Jakob F.
    [J]. IDIMT-2008: MANAGING THE UNMANAGEABLE, 2008, 25 : 431 - +
  • [4] Security enhancement on mobile devices using steganography
    Iqbal, S
    Saberwal, V
    Alameldin, T
    [J]. ISWS '05: Proceedings of the 2005 International Symposium on Web Services and Applications, 2005, : 29 - 34
  • [5] An Experimental Framework for Investigating Security and Privacy of IoT Devices
    Tekeoglu, Ali
    Tosun, Ali Saman
    [J]. INTELLIGENT, SECURE, AND DEPENDABLE SYSTEMS IN DISTRIBUTED AND CLOUD ENVIRONMENTS (ISDDC 2017), 2017, 10618 : 63 - 83
  • [6] Security and Privacy Framework for Ubiquitous Healthcare IoT Devices
    Alkeem, Ebrahim A. L.
    Yeun, Chan Yeob
    Zemerly, M. Jamal
    [J]. 2015 10TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2015, : 70 - 75
  • [7] Security and Privacy for Smart, Connected, and Mobile IoT Devices and Platforms
    Andersson, Karl
    You, Ilsun
    Palmieri, Francesco
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [8] A Framework to Identify Security and Privacy Issues of Smart Home Devices
    Varghese, Joel
    Hayajneh, Thaier
    [J]. 2018 9TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2018, : 135 - 143
  • [9] A Framework for Enhancing Security and Privacy on Unmodified Mobile Operating Systems
    Krupp, Brian
    Sridhar, Nigamanth
    Zhao, Wenbing
    [J]. 2013 33RD IEEE INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS (ICDCSW 2013), 2013, : 404 - 409
  • [10] Framework for Security and Privacy Management for Mobile Middleware Based on Tuple
    Nguessan, D.
    Martini, J. S. C.
    [J]. IEEE LATIN AMERICA TRANSACTIONS, 2015, 13 (08) : 2757 - 2762