课题基金 / 基金详情

TWC: Small: Develop Fine-Grained Access Control for Third-Party Components in Mobile Systems

TWC: Small: Develop Fine-Grained Access Control for Third-Party Components in Mobile Systems
TWC:小型:为移动系统中的第三方组件开发细粒度的访问控制
批准号:
1318814
负责人:
Wenliang Du
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-08-01 至 2017-07-31

项目摘要

项目成果

Wenliang Du的其他基金

相似基金

相关文献

中文摘要
翻译
智能手机和平板电脑正在被广泛使用,在这种普遍使用的情况下,保护移动系统至关重要。移动系统的一个独特功能是,许多应用程序结合了第三方组件,如广告、社交网络API和WebView组件(运行第三方Java代码)。使用第三方组件,应用程序开发人员开发的代码和来自第三方的代码在相同的上下文中以相同的权限执行。没有开发访问控制系统来将第一方应用程序代码的特权与第三方组件的特权分开。这导致了过度特权的问题。该项目的目标是开发适当的访问控制系统,以弥补第三方组件带来的风险。这一开发基于对各种第三方组件、它们如何与应用程序交互、哪些功能是可取的以及它们的保护需求的系统研究。该项目通过三管齐下的方法实现了这一目标:(1)向WebView添加新的访问控制,以控制与第三方代码的交互;(2)在应用程序中添加包级访问控制,以防止过度权限;以及(3)使用可视元素隔离第三方组件。这个项目可以让移动系统开发人员更深入地了解系统中的安全问题,向他们建议如何更好地设计出移动系统所需要的安全属性,并最终提高移动系统的安全性。
英文摘要
Smartphones and tablets are being used widely, and with such a pervasive use, protecting mobile systems is of critical importance. One of the unique features in mobile systems is that many applications incorporate third-party components, such as advertisement, social-network APIs, and the WebView component (that runs third-party JavaScript code). With third-party components, the code developed by application developers and the code from third parties are executed within the same context and with the same privilege. No access control system is developed to separate the privilege of the first-party application code from that of third-party components. This has resulted in over-privilege issues. The objective of this project is to develop adequate access control systems to remedy the risks introduced by third-party components. The development is based on a systematic study of various third-party components, how they interact with applications, what features are desirable, and what their protection needs are. The project meets this objective using a three-pronged approach: (1) add new access controls to WebView to control the interactions with third-party code; (2) add package-level access controls within apps to prevent over-privilege; and (3) isolate third-party components with visual elements. This project can offer mobile system developers a deeper understanding of the security problems in the systems, suggest to them how better to design into mobile systems desired security properties, and eventually improve the security of mobile systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: EDU: Building an Internet Emulator for Cybersecurity Education
  • 批准号:
    2214916
  • 项目类别:
    Standard Grant
  • 资助金额:
    $39.92万
  • 财政年份:
    2022
  • 负责人:
    Wenliang Du
  • 依托单位:
SaTC: CORE: Small: Expanding TrustZone: Enabling Mobile Apps to Transparently Leverage TrustZone for Attestation and Data Protection
  • 批准号:
    1718086
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.73万
  • 财政年份:
    2017
  • 负责人:
    Wenliang Du
  • 依托单位:
Spreading SEEDs: Large-Scale Dissemination of Hands-on Labs for Security Education
  • 批准号:
    1303306
  • 项目类别:
    Standard Grant
  • 资助金额:
    $82.74万
  • 财政年份:
    2014
  • 负责人:
    Wenliang Du
  • 依托单位:
EDU: Collaborative: Bolstering Security Education through Transiting Research on Browser Security
  • 批准号:
    1318883
  • 项目类别:
    Standard Grant
  • 资助金额:
    $8.99万
  • 财政年份:
    2013
  • 负责人:
    Wenliang Du
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: