IAC: On the Feasibility of Utilizing Neural Signals for Access Control

IAC: On the Feasibility of Utilizing Neural Signals for Access Control
复制标题

DOI:
10.1145/3274694.3274713
复制
发表时间:
2018-12
期刊:
Proceedings of the 34th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
M. L. Rahman;Ajaya Neupane;Chengyu Song
M. L. Rahman;Ajaya Neupane;Chengyu Song
中科院分区:
其他
文献类型:
--
作者:
M. L. Rahman;Ajaya Neupane;Chengyu Song

文献摘要

相似文献

访问控制是操作系统(OS)的核心安全机制。理想情况下,访问控制系统应执行上下文完整性,即应用程序只能访问用户期望的安全性和隐私敏感资源。不幸的是,现有的访问控制系统,包括iOS和Android等现代操作系统中的许可系统,都无法执行上下文完整性,因此使应用程序滥用其权限。强制执行环境完整性的一种天真的方法是每次访问敏感资源时提示用户,但这会很快导致习惯。最先进的解决方案包括(1)用户驱动的访问控制,该解决方案将预定义的上下文绑定到受保护的GUI元素,以及(2)根据其先前的行为和隐私偏好来预测用户的授权决策。但是,先前的研究表明,第一种方法容易受到攻击(例如,clickjacking),而我挑战了第二种方法,因为很难推断上下文。在这项工作中,我们探讨了一种新颖的方法来实施上下文完整性的可行性 - 通过推断用户从其神经信号中的给定上下文中要做的工作;然后自动授权访问该任务所需的预定义敏感资源集。我们进行了一项全面的用户研究,其中包括41位参与者,当他们执行需要访问敏感资源的任务时,我们收集了他们的神经信号。在预处理和提取功能之后,我们训练了机器学习分类器,以推断用户想要执行的任务。实验结果表明,分类器能够推断出高水平的意图,例如拍照,加权平均精度为88%。
Access control is the core security mechanism of an operating system (OS). Ideally, the access control system should enforce context integrity, i.e., an application can only access security and privacy sensitive resources expected by users. Unfortunately, existing access control systems, including the permission systems in modern OS like iOS and Android, all fail to enforce context integrity thus allow apps to abuse their permissions. A naive approach to enforce context integrity is to prompt users every time a sensitive resource is accessed, but this will quickly lead to habituation. The state-of-art solutions include (1) user-driven access control, which binds a predefined context to protected GUI elements and (2) predicting users' authorization decision based on their previous behaviors and privacy preferences. However, previous studies have shown that the first approach is vulnerable to attacks (e.g., clickjacking) and the second approach i challenging to implement as it is difficult to infer the context. In this work, we explore the feasibility of a novel approach to enforce the context integrity---by inferring what task users want to do under the given context from their neural signals; then automatically authorizes access to a predefined set of sensitive resources that are necessary for that task. We conducted a comprehensive user study including 41 participants where we collected their neural signals when they were performing tasks that required access to sensitive resources. After preprocessing and features extraction, we trained machine learning classifier to infer what kind of tasks a user wants to perform. The experiment results show that the classifier was able to infer the high-level intents like take a photo with a weighted average precision of 88%.