TWC: Medium: Collaborative: Improving Mobile-Application Security via Text Analytics
TWC: Medium: Collaborative: Improving Mobile-Application Security via Text Analytics
批准号:
1513690
负责人:
William Enck
金额:
$30.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-07-01 至 2019-06-30
中文摘要
安全策略通常基于时间上下文(例如,一天中的时间)和环境上下文(例如,地理位置)来做出访问决策。操作系统的访问控制策略经常考虑执行上下文(例如,用户ID、程序参数)。然而,很少有人将用户期望上下文合并到安全决策机制中。文本构件提供了用户期望上下文的来源。在查找、安装和运行软件时,会向用户显示自然语言文本,例如文本功能描述、许可请求、隐私声明和用户界面文本。本研究旨在通过将面向用户的自然语言文本与安全操作联系起来,使用期望上下文来改进安全决策。这项研究特别关注移动应用程序,在做出安全决策时结合期望上下文。移动应用程序提供特定形式的用户文本和安全操作。本研究考虑了应用程序的描述或用户界面文本与不同粒度的安全操作之间的关系。这项研究奠定了技术和工具的基础,这些技术和工具可以告知移动设备用户安装移动应用程序所涉及的安全和隐私问题。作为更广泛的影响,这项研究使开发人员能够生产更安全的移动应用程序,并使用户能够使用更安全的移动应用程序。
英文摘要
Security policies often base access decisions on temporal context (e.g., time of day) and environmental context (e.g., geographic location). Access control policies for operating systems frequently consider execution context (e.g., user ID, program arguments). However, little has been done to incorporate user expectation context into security decision mechanisms. Text artifacts provide a source of user expectation context. When finding, installing, and running software, users are shown natural language text, e.g., textual functionality descriptions, permission requests, privacy notices, and user interface text. This research aims to improve security decisions using expectation context, by relating user-facing natural language text with security operations.This research focuses specifically on mobile applications by incorporating expectation context when making security decisions. Mobile applications provide specific forms of user text and security operations. This research considers the relationship between an application's description or user interface text and different granularities of security operations. The research forms the foundation for techniques and tools that inform mobile-device users of the security and privacy implications of installing mobile applications. As broader impacts, this research enables developers to produce more secure mobile applications and enables users to use more secure mobile applications.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Enabling Practically Secure Cellular Infrastructure
-
批准号:2054911
-
项目类别:Standard Grant
-
资助金额:$60.2万
-
财政年份:2022
-
负责人:William Enck
-
依托单位:
Collaborative Research: Conference: 2022 Secure and Trustworthy Cyberspace PI Meeting
-
批准号:2205939
-
项目类别:Standard Grant
-
资助金额:$4.72万
-
财政年份:2022
-
负责人:William Enck
-
依托单位:
SaTC: CORE: Small: Detecting Vulnerabilities and Remediations in Software Dependencies
-
批准号:1946273
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2020
-
负责人:William Enck
-
依托单位:
NSF Travel Grant Support for ACM WiSec 2016
-
批准号:1641220
-
项目类别:Standard Grant
-
资助金额:$0.5万
-
财政年份:2016
-
负责人:William Enck
-
依托单位:
CAREER: Secure OS Views for Modern Computing Platforms
-
批准号:1253346
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2013
-
负责人:William Enck
-
依托单位:
TWC: Frontier: Collaborative: Rethinking Security in the Era of Cloud Computing
-
批准号:1330553
-
项目类别:Continuing Grant
-
资助金额:$75.0万
-
财政年份:2013
-
负责人:William Enck
-
依托单位:
TWC: Small: Collaborative: Characterizing the Security Limitations of Accessing the Mobile Web
-
批准号:1222680
-
项目类别:Standard Grant
-
资助金额:$16.7万
-
财政年份:2012
-
负责人:William Enck
-
依托单位:
海外基金