Context-Specific Access Control: Conforming Permissions With User Expectations
Context-Specific Access Control: Conforming Permissions With User Expectations
复制标题
上下文特定的访问控制:使权限符合用户期望
DOI:
10.1145/2808117.2808121
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
H. Madhyastha
中科院分区:
文献类型:
--
作者:
Amir Rahmati;H. Madhyastha
Current mobile platforms take an all-or-nothing approach to assigning permissions to applications. Once a user grants an application permission to access a particular resource, the application can use that permission whenever it executes thereafter. This enables an application to access privacy sensitive resources even when they are not needed for it to perform its expected functions. In this paper, we introduce "Context-Specific Access Control" (CSAC) as a design approach towards enforcing the principle of least privilege. CSAC's goal is to enable a user to ensure that, at any point in time, an application has access to those resources which she expects are needed by the application component with which she is currently interacting. We study 100 popular applications from Google Play store and find that existing applications are amenable to CSAC as most applications' use of privacy sensitive resources is limited to a small number of contexts. Furthermore, via dynamic analysis of the 100 applications and a small-scale user study, we find that CSAC does not prohibitively increase the number of access control decisions that users need to make.