• DocumentCode
    2845038
  • Title

    Flexible Data-Driven Security for Android

  • Author

    Feth, Denis ; Pretschner, Alexander

  • Author_Institution
    Fraunhofer Inst. for Exp. Software Eng. IESE, Kaiserslautern, Germany
  • fYear
    2012
  • fDate
    20-22 June 2012
  • Firstpage
    41
  • Lastpage
    50
  • Abstract
    Android allows users to cancel the installation of apps whenever requested permissions to resources seem inappropriate from their point of view. Since permissions can neither be granted individually nor changed after installation, this results in rather coarse, and often too liberal, access rules. We propose a more fine-grained security system beyond the standard permission system. With our system, it is possible to enforce complex policies that are built on temporal, cardinality, and spatial conditions ("notify if data is used after thirty days\´\´, "blur data outside company\´s premises\´\´, etc.). Enforcement can be done by means of modification or inhibition of certain events and the execution of additional actions. Leveraging recent advances in information flow tracking technology, our policies can also pertain to data rather than single representations of that data. For instance, we can prohibit a movie from being played more than twice even if several copies have been created. We present design and implementation of the system and provide a security and performance analysis.
  • Keywords
    mobile computing; security of data; android; apps installation; fine grained security system; flexible data driven security; information flow tracking technology; requested permissions; standard permission system; Androids; Companies; Humanoid robots; Monitoring; Runtime; Security; Smart phones; Access Control; Android; Information Flow; Security; Usage Control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference on
  • Conference_Location
    Gaithersburg, MD
  • Print_ISBN
    978-1-4673-2067-2
  • Type

    conf

  • DOI
    10.1109/SERE.2012.14
  • Filename
    6258293