USENIX Security2019Top-tier venue
EnTrust: Regulating Sensor Access by Cooperating Programs via Delegation Graphs
Giuseppe Petracca, Yuqiong Sun, Ahmad Atamli-Reineh, Patrick D. McDaniel, Jens Grossklags, Trent Jaeger
Abstract
Modern operating systems support a cooperating program abstraction that, instead of placing all functionality into a single program, allows diverse programs to cooperate to complete tasks requested by users. However, untrusted programs may exploit such interactions to spy on users through device sensors by causing privileged system services to misuse their permissions, or to forward user requests to malicious programs inadvertently. Researchers have previously explored methods to restrict access to device sensors based on the state of the user interface that elicited the user input or based on the set of cooperating programs, but the former approach does not consider cooperating programs and the latter approach has been found to be too restrictive for many cases. In this paper, we propose EnTrust, an authorization system that tracks the processing of input events across programs for eliciting approvals from users for sensor operations. EnTrust constructs delegation graphs by linking input events to cooperation events among programs that lead to sensor operation requests, then uses such delegation graphs for eliciting authorization decisions from users. To demonstrate this approach, we implement the EnTrust authorization system for Android OS. In a laboratory study, we show that attacks can be prevented at a much higher rate (47-67% improvement) compared to the first-use approach. Our field study reveals that EnTrust only requires a user effort comparable to the first-use approach while incurring negligible performance (<1% slowdown) and memory overheads (5.5 KB per program).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8e602569-6e24-487f-8dde-bcaa6e9c6ab4Cited by top-tier papers2
- Towards Automated Safety Vetting of Smart Contracts in Decentralized ApplicationsYue Duan, Xin Zhao, Yu Pan, Shucheng Li et al.CCS 2022 · 22 citations
- Hey Kimya, Is My Smart Speaker Spying on Me? Taking Control of Sensor Privacy Through Isolation and AmnesiaPiet De Vaere, Adrian PerrigUSENIX Security 2023
Builds on7
- The Spyware Used in Intimate Partner ViolenceRahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sam Havron et al.S&P 2018 · 167 citations
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon et al.S&P 2017 · 156 citations
- SmarPer: Context-Aware and Automatic Runtime-Permissions for Mobile DevicesKatarzyna Olejnik, Italo Dacosta, Joana Soares Machado, Kévin Huguenin et al.S&P 2017 · 102 citations
- SoK: Lessons Learned from Android Security Research for Appified Software PlatformsYasemin Acar, Michael Backes, Sven Bugiel, Sascha Fahl et al.S&P 2016 · 101 citations
- Practical DIFC Enforcement on AndroidAdwait Nadkarni, Benjamin Andow, William Enck, Somesh JhaUSENIX Security 2016 · 57 citations
Related papers
- AWare: Preventing Abuse of Privacy-Sensitive Sensors via Operation BindingsGiuseppe Petracca, Ahmad Atamli-Reineh, Yuqiong Sun, Jens Grossklags et al.USENIX Security 2017 · 35 citations
- AUDACIOUS: User-Driven Access Control with Unmodified Operating SystemsTalia Ringer, Dan Grossman, Franziska RoesnerCCS 2016 · 38 citations
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang et al.USENIX Security 2017 · 231 citations
- 6thSense: A Context-aware Sensor-based Attack Detector for Smart DevicesAmit Kumar Sikder, Hidayet Aksu, A. Selcuk UluagacUSENIX Security 2017 · 129 citations
- WAVE: A Decentralized Authorization Framework with Transitive DelegationMichael P. Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro et al.USENIX Security 2019 · 66 citations
