课题基金 / 基金详情

TWC: Small: Develop Fine-Grained Access Control for Third-Party Components in Mobile Systems

TWC: Small: Develop Fine-Grained Access Control for Third-Party Components in Mobile Systems
TWC:小型:为移动系统中的第三方组件开发细粒度的访问控制
批准号:
1318814
负责人:
Wenliang Du
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-08-01 至 2017-07-31

项目摘要

项目成果

Wenliang Du的其他基金

相似基金

相关文献

中文摘要
翻译
智能手机和平板电脑正在被广泛使用,由于使用如此普遍,保护移动系统至关重要。移动系统的一个独特特性是,许多应用程序都包含第三方组件,例如广告、社交网络api和WebView组件(运行第三方JavaScript代码)。对于第三方组件,应用程序开发人员开发的代码和来自第三方的代码在相同的上下文中以相同的权限执行。没有开发访问控制系统来将第一方应用程序代码的权限与第三方组件的权限分开。这导致了过度特权问题。该项目的目标是开发适当的访问控制系统,以补救第三方组成部分带来的风险。该开发基于对各种第三方组件的系统研究,包括它们如何与应用程序交互、需要哪些特性以及它们的保护需求。该项目采用了三管齐下的方法来实现这一目标:(1)向WebView添加新的访问控制,以控制与第三方代码的交互;(2)在应用程序中添加包级访问控制,防止权限过大;(3)用可视化元素隔离第三方组件。这个项目可以让移动系统开发者更深入地了解系统中的安全问题,并建议他们如何更好地设计到移动系统所需的安全属性,最终提高移动系统的安全性。
英文摘要
Smartphones and tablets are being used widely, and with such a pervasive use, protecting mobile systems is of critical importance. One of the unique features in mobile systems is that many applications incorporate third-party components, such as advertisement, social-network APIs, and the WebView component (that runs third-party JavaScript code). With third-party components, the code developed by application developers and the code from third parties are executed within the same context and with the same privilege. No access control system is developed to separate the privilege of the first-party application code from that of third-party components. This has resulted in over-privilege issues. The objective of this project is to develop adequate access control systems to remedy the risks introduced by third-party components. The development is based on a systematic study of various third-party components, how they interact with applications, what features are desirable, and what their protection needs are. The project meets this objective using a three-pronged approach: (1) add new access controls to WebView to control the interactions with third-party code; (2) add package-level access controls within apps to prevent over-privilege; and (3) isolate third-party components with visual elements. This project can offer mobile system developers a deeper understanding of the security problems in the systems, suggest to them how better to design into mobile systems desired security properties, and eventually improve the security of mobile systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: EDU: Building an Internet Emulator for Cybersecurity Education
  • 批准号:
    2214916
  • 项目类别:
    Standard Grant
  • 资助金额:
    $39.92万
  • 财政年份:
    2022
  • 负责人:
    Wenliang Du
  • 依托单位:
SaTC: CORE: Small: Expanding TrustZone: Enabling Mobile Apps to Transparently Leverage TrustZone for Attestation and Data Protection
  • 批准号:
    1718086
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.73万
  • 财政年份:
    2017
  • 负责人:
    Wenliang Du
  • 依托单位:
Spreading SEEDs: Large-Scale Dissemination of Hands-on Labs for Security Education
  • 批准号:
    1303306
  • 项目类别:
    Standard Grant
  • 资助金额:
    $82.74万
  • 财政年份:
    2014
  • 负责人:
    Wenliang Du
  • 依托单位:
EDU: Collaborative: Bolstering Security Education through Transiting Research on Browser Security
  • 批准号:
    1318883
  • 项目类别:
    Standard Grant
  • 资助金额:
    $8.99万
  • 财政年份:
    2013
  • 负责人:
    Wenliang Du
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: