SPE: Security and Privacy Enhancement Framework for Mobile Devices

被引:13
|
作者
Krupp, Brian [1 ]
Sridhar, Nigamanth [2 ]
Zhao, Wenbing [2 ]
机构
[1] Baldwin Wallace Univ, Comp Sci Dept, Berea, OH 44145 USA
[2] Cleveland State Univ, Dept Elect Engn & Comp Sci, Cleveland, OH USA
基金
美国国家科学基金会;
关键词
Mobile security; mobile privacy; sensing; encryption; iOS; android;
D O I
10.1109/TDSC.2015.2465965
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present a security and privacy enhancement (SPE) framework for unmodified mobile operating systems. SPE introduces a new layer between the application and the operating system and does not require a device be jailbroken or utilize a custom operating system. We utilize an existing ontology designed for enforcing security and privacy policies on mobile devices to build a policy that is customizable. Based on this policy, SPE provides enhancements to native controls that currently exist on the platform for privacy and security sensitive components. SPE allows access to these components in a way that allows the framework to ensure the application is truthful in its declared intent and ensure that the user's policy is enforced. In our evaluation we verify the correctness of the framework and the computing impact on the device. Additionally, we discovered security and privacy issues in several open source applications by utilizing the SPE Framework. From our findings, if SPE is adopted by mobile operating systems producers, it would provide consumers and businesses the additional privacy and security controls they demand and allow users to be more aware of security and privacy issues with applications on their devices.
引用
收藏
页码:433 / 446
页数:14
相关论文
共 50 条
  • [41] Security Issues for Mobile Devices
    Andreeski, Cvetko
    [J]. CYBER SECURITY AND RESILIENCY POLICY FRAMEWORK, 2014, 38 : 36 - 48
  • [42] IEEE Services Visionary Track on Security and Privacy Engineering (SPE 2015)
    Ardagna, Claudio A.
    Jensen, Meiko
    Martin, Miguel Vargas
    [J]. 2015 IEEE World Congress on Services, 2015, : 151 - 151
  • [43] A Survey on Security for Mobile Devices
    La Polla, Mariantonietta
    Martinelli, Fabio
    Sgandurra, Daniele
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2013, 15 (01): : 446 - 471
  • [44] Editorial: Security of Mobile Devices
    Shukla, Sandeep K.
    [J]. ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2017, 16 (04)
  • [45] Policy framework for security and privacy management
    Karat, J.
    Karat, C. -M.
    Bertino, E.
    Li, N.
    Ni, Q.
    Brodie, C.
    Lobo, J.
    Calo, S. B.
    Cranor, L. F.
    Kumaraguru, P.
    Reeder, R. W.
    [J]. IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2009, 53 (02)
  • [46] Security enhancement on mobile commerce
    Kwon, EK
    Cho, YG
    Chae, KJ
    [J]. HUMAN SOCIETY AND THE INTERNET, PROCEEDINGS: INTERNET-RELATED SOCIO-ECONOMIC ISSUES, 2001, 2105 : 164 - 176
  • [47] Security Framework for VANET for Privacy Preservation
    Chetan, V. S.
    Benni, N. S.
    Bhushan, C.
    [J]. 2013 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND NETWORKING TECHNOLOGIES (ICCCNT), 2013,
  • [48] Third-year medical students' knowledge of privacy and security issues concerning mobile devices
    Whipple, Elizabeth C.
    Allgood, Kacy L.
    Larue, Elizabeth M.
    [J]. MEDICAL TEACHER, 2012, 34 (08) : E532 - E548
  • [49] Reflections on U-PriSM 2: The Second Workshop on Usable Privacy and Security for Mobile Devices
    Chiasson, Sonia
    Crawford, Heather
    Egelman, Serge
    Irani, Pourang
    [J]. INTERNATIONAL JOURNAL OF MOBILE HUMAN COMPUTER INTERACTION, 2014, 6 (02) : 73 - 78
  • [50] The Privacy Calculus: Mobile Apps and User Perceptions of Privacy and Security
    Fife, Elizabeth
    Orjuela, Juan
    [J]. INTERNATIONAL JOURNAL OF ENGINEERING BUSINESS MANAGEMENT, 2012, 4