AWare: Preventing Abuse of Privacy-Sensitive Sensors via Operation Bindings
Giuseppe Petracca, Ahmad Atamli-Reineh, Yuqiong Sun, Jens Grossklags, Trent Jaeger
摘要
System designers have long struggled with the challenge of determining how to control when untrusted applications may perform operations using privacy-sensitive sensors securely and effectively. Current systems request that users authorize such operations once (i.e., on install or first use), but malicious applications may abuse such authorizations to collect data stealthily using such sensors. Proposed research methods enable systems to infer the operations associated with user input events, but malicious applications may still trick users into allowing unexpected, stealthy operations. To prevent users from being tricked, we propose to bind applications' operation requests to the associated user input events and how they were obtained explicitly, enabling users to authorize operations on privacy-sensitive sensors unambiguously and reuse such authorizations. To demonstrate this approach, we implement the AWare authorization framework for Android, extending the Android Middleware to control access to privacy-sensitive sensors. We evaluate the effectiveness of AWare in: (1) a laboratory-based user study, finding that at most 7% of the users were tricked by examples of four types of attacks when using AWare, instead of 85% on average for prior approaches; (2) a field study, showing that the user authorization effort increases by only 2.28 decisions on average per application; (3) a compatibility study with 1,000 of the most-downloaded Android applications, demonstrating that such applications can operate effectively under AWare.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial SensorsYazhou Tu, Zhiqiang Lin, Insup Lee, Xiali HeiUSENIX Security 2018 · 被引用 132 次
- SoK: A Minimalist Approach to Formalizing Analog Sensor SecurityChen Yan, Hocheol Shin, Connor Bolton, Wenyuan Xu 等S&P 2020 · 被引用 86 次
- Towards Automated Safety Vetting of Smart Contracts in Decentralized ApplicationsYue Duan, Xin Zhao, Yu Pan, Shucheng Li 等CCS 2022 · 被引用 22 次
- EnTrust: Regulating Sensor Access by Cooperating Programs via Delegation GraphsGiuseppe Petracca, Yuqiong Sun, Ahmad Atamli-Reineh, Patrick D. McDaniel 等USENIX Security 2019 · 被引用 10 次
- Hey Kimya, Is My Smart Speaker Spying on Me? Taking Control of Sensor Privacy Through Isolation and AmnesiaPiet De Vaere, Adrian PerrigUSENIX Security 2023
它引用的顶会 Paper2
相关 Paper
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang 等USENIX Security 2017 · 被引用 231 次
- 6thSense: A Context-aware Sensor-based Attack Detector for Smart DevicesAmit Kumar Sikder, Hidayet Aksu, A. Selcuk UluagacUSENIX Security 2017 · 被引用 129 次
- Fine-Grained In-Context Permission Classification for Android Apps Using Control-Flow Graph EmbeddingVikas Kumar Malviya, Yan Naing Tun, Chee Wei Leow, Ailys Tee Xynyn 等ASE 2023 · 被引用 4 次
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon 等S&P 2017 · 被引用 156 次
- What You Experience is What We Collect: User Experience Based Fine-Grained Permissions for Everyday Augmented RealityMelvin Abraham, Mark McGill, Mohamed KhamisCHI 2024 · 被引用 18 次
