AUDACIOUS: User-Driven Access Control with Unmodified Operating Systems
Talia Ringer, Dan Grossman, Franziska Roesner
摘要
User-driven access control improves the coarse-grained access control of current operating systems (particularly in the mobile space) that provide only all-or-nothing access to a resource such as the camera or the current location. By granting appropriate permissions only in response to explicit user actions (for example, pressing a camera button), userdriven access control better aligns application actions with user expectations. Prior work on user-driven access control has relied in essential ways on operating system (OS) modifications to provide applications with uncompromisable access control gadgets, distinguished user interface (UI) elements that can grant access permissions. This work presents a design, implementation, and evaluation of user-driven access control that works with no OS modifications, thus making deployability and incremental adoption of the model more feasible. We develop (1) a userlevel trusted library for access control gadgets, (2) static analyses to prevent malicious creation of UI events, illegal flows of sensitive information, and circumvention of our library, and (3) dynamic analyses to ensure users are not tricked into granting permissions. In addition to providing the original user-driven access control guarantees, we use static information flow to limit where results derived from sensitive sources may flow in an application. Our implementation targets Android applications. We port open-source applications that need interesting resource permissions to use our system. We determine in what ways user-driven access control in general and our implementation in particular are good matches for real applications. We demonstrate that our system is secure against a variety of attacks that malware on Android could otherwise mount.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon 等S&P 2017 · 被引用 156 次
- AWare: Preventing Abuse of Privacy-Sensitive Sensors via Operation BindingsGiuseppe Petracca, Ahmad Atamli-Reineh, Yuqiong Sun, Jens Grossklags 等USENIX Security 2017 · 被引用 35 次
- AppMoD: Helping Older Adults Manage Mobile Security with Online Social HelpZhiyuan Wan, Lingfeng Bao, Debin Gao, Eran Toch 等UbiComp 2020 · 被引用 27 次
- Towards Automating Data Access Permissions in AI AgentsYuhao Wu, Ke Yang, Franziska Roesner, Tadayoshi Kohno 等S&P 2026 · 被引用 22 次
- Towards Automated Safety Vetting of Smart Contracts in Decentralized ApplicationsYue Duan, Xin Zhao, Yu Pan, Shucheng Li 等CCS 2022 · 被引用 22 次
相关 Paper
- DocFlow: Extracting Taint Specifications from Software DocumentationMarcos Tileria, Jorge Blasco, Santanu Kumar DashICSE 2024 · 被引用 5 次
- EnTrust: Regulating Sensor Access by Cooperating Programs via Delegation GraphsGiuseppe Petracca, Yuqiong Sun, Ahmad Atamli-Reineh, Patrick D. McDaniel 等USENIX Security 2019 · 被引用 10 次
- Resolving the Predicament of Android Custom PermissionsGüliz Seray Tuncay, Soteris Demetriou, Karan Ganju, Carl A. GunterNDSS 2018 · 被引用 51 次
- PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android SystemsYu Tsung Lee, William Enck, Haining Chen, Hayawardh Vijayakumar 等USENIX Security 2021 · 被引用 17 次
- Bringing Balance to the Force: Dynamic Analysis of the Android Application FrameworkAbdallah Dawoud, Sven BugielNDSS 2021
