TKPERM: Cross-platform Permission Knowledge Transfer to Detect Overprivileged Third-party Applications
Faysal Hossain Shezan, Kaiming Cheng, Zhen Zhang, Yinzhi Cao, Yuan Tian
摘要
Permission-based access control enables users to manage and control their sensitive data for third-party applications. In an ideal scenario, third-party application includes enough details to illustrate the usage of such data, while the reality is that many descriptions of third-party applications are vague about their security or privacy activities. As a result, users are left with insufficient details when granting sensitive data to these applications. Prior works, such as WHYPER and AutoCog, have addressed the aforementioned problem via a so-called permission correlation system. Such a system correlates thirdparty applications’ description with their requested permissions and determines an application as overprivileged, if a mismatch between the requested permission and the description is found. However, although prior works are successful on their own platforms, such as Android eco-system, they are not directly applicable to new platforms, such as Chrome extensions and IFTTT, without extensive data labeling and parameter tuning. In this paper, we design, implement, and evaluate a novel system, called TKPERM, which transfers knowledges of permission correlation systems across platforms. Our key idea is that these varied platforms with different use cases—like smartphones, IoTs, and desktop browsers—are all user-facing and thus allow the knowledges to be transferrable across platforms. Particularly, we adopt a greedy selection algorithm that picks the best source domains to transfer to the target permission on a new platform. TKPERM achieves 90.02% overall F1 score after transfer, which is 12.62% higher than the one of a model trained directly on the target domain without transfer. Particularly, TKPERM has 91.83% F1 score on IFTTT, 89.13% F1 score on Chrome-Extension, and 89.1% F1 score on SmartThings. TKPERM also successfully identified many real-world overprivileged applications, such as a gaming hub requesting location permissions without legitimate use.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Don't Bite Off More than You Can Chew: Investigating Excessive Permission Requests in Trigger-Action IntegrationsLiuhuo Wan, Kailong Wang, Kulani Mahadewa, Haoyu Wang 等WWW 2024 · 被引用 4 次
- CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property GraphFaysal Hossain Shezan, Zihao Su, Mingqing Kang, Nicholas Phair 等NDSS 2023
它引用的顶会 Paper4
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 被引用 684 次
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato 等USENIX Security 2016 · 被引用 296 次
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang 等USENIX Security 2017 · 被引用 231 次
- FlowCog: Context-aware Semantics Extraction and Analysis of Information Flow Leaks in Android AppsXiang Pan, Yinzhi Cao, Xuechao Du, Boyuan He 等USENIX Security 2018 · 被引用 39 次
相关 Paper
- Practical Data Access Minimization in Trigger-Action PlatformsYunang Chen, Mohannad Alhanahnah, Andrei Sabelfeld, Rahul Chatterjee 等USENIX Security 2022
- ContexloT: Towards Providing Contextual Integrity to Appified IoT PlatformsYunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati 等NDSS 2017 · 被引用 325 次
- Wear's my Data? Understanding the Cross-Device Runtime Permission Model in WearablesDoguhan Yeke, Muhammad Ibrahim, Güliz Seray Tuncay, Habiba Farrukh 等S&P 2024 · 被引用 12 次
- EmPoWeb: Empowering Web Applications with Browser ExtensionsDolière Francis SoméS&P 2019 · 被引用 60 次
- SmarPer: Context-Aware and Automatic Runtime-Permissions for Mobile DevicesKatarzyna Olejnik, Italo Dacosta, Joana Soares Machado, Kévin Huguenin 等S&P 2017 · 被引用 102 次
