EAGER: Securing Smartphone Applications Against Rapidly Expanding Accessibility-Based Attacks
EAGER: Securing Smartphone Applications Against Rapidly Expanding Accessibility-Based Attacks
批准号:
1650000
负责人:
Mark Grechanik
金额:
$9.71万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-08-01 至 2017-07-31
中文摘要
该项目将研究图形用户界面(GUI)应用程序,这些应用程序对残疾用户来说是困难的,如视觉、运动、记忆、听力、交流等。目前,移动辅助应用使用专门的可访问性技术提供增强服务,这些技术从根本上是不安全的,从而使用户面临各种攻击。这些袭击正在出现在媒体上,并引起极大的关注。辅助功能应用程序是“可用安全”问题的主要例子,经常在大学课程中用来说明在启用所需功能和保护设备免受攻击之间的权衡。通常,保护用户安全的方法是警告他们不要使用他们需要的某些功能,因此用户是安全的,但不能完全发挥作用。这个探索性项目将研究一系列软件,以更好地了解安全问题如何影响残疾用户。它将使用这些新知识来探索指导软件分析的新抽象和算法。将开发一个原型安全测试工具,演示如何在实现可访问性的同时避免违反安全约束。对移动辅助应用的深入理解可能会为泛在设备中的可用安全开辟新的研究方向。
英文摘要
The project will study graphical user interface (GUI) applications that are difficult for users with disabilities such as vision, movement, remembering, hearing, communicating, etc.. Currently, mobile assistive applications provide enhancement services using specialized accessibility technologies that are fundamentally insecure, thus exposing users to a variety of attacks. These attacks are showing up in the press and are of great concern. Accessibility applications are prime examples of "usable security" issues, often being used in college courses to illustrate the tradeoffs between enabling needed functionality versus keeping devices secure from attack. Typically, the method of keeping users safe is to warned them to not use certain functionality that they need, thus users are safe but not able to fully function. The exploratory project will study a body of software to better understand how security issues affect users with disabilities. It will use this new knowledge to explore new abstractions and algorithms that guide analyses of the software. A prototype security testing tool will be developed that demonstrates how to avoid violation of security constraints while enabling accessibility. A deeper understanding of mobile assistive applications may open up new research directions for usable security in ubiquitous devices.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Generating smartphone phishing applications for deception based defense
生成智能手机网络钓鱼应用程序以进行基于欺骗的防御
DOI:
--
发表时间:
2017
期刊:
Master thesis
影响因子:
--
作者:
[Sharma, Kruti]
通讯作者:
Sharma, Kruti
SaTC: CORE: Small: Defense by Deception of Smartphone Software Applications For Users With Disabilities
-
批准号:2129739
-
项目类别:Standard Grant
-
资助金额:$48.36万
-
财政年份:2022
-
负责人:Mark Grechanik
-
依托单位:
SHF:Small:Proving User Interface Testing Programs Correct
-
批准号:2120142
-
项目类别:Standard Grant
-
资助金额:$47.65万
-
财政年份:2021
-
负责人:Mark Grechanik
-
依托单位:
SHF: Small:Automatically Synthesizing System and Integration Tests
-
批准号:1908094
-
项目类别:Standard Grant
-
资助金额:$37.89万
-
财政年份:2019
-
负责人:Mark Grechanik
-
依托单位:
SHF: Small: Automatically Localizing Functional Faults In Deployed Software Applications
-
批准号:1615563
-
项目类别:Standard Grant
-
资助金额:$35.09万
-
财政年份:2016
-
负责人:Mark Grechanik
-
依托单位:
I-Corps: Automatically Localizing Functional Faults In Deployed Software Applications
-
批准号:1547597
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2015
-
负责人:Mark Grechanik
-
依托单位:
Travel Support For ACM/IEEE International Conference on Software Engineering (ICSE 2014)
-
批准号:1360923
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2014
-
负责人:Mark Grechanik
-
依托单位:
III: Small: Collaborative Research: Linking Evolving Software Requirements and Acceptance Tests
-
批准号:1217928
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2012
-
负责人:Mark Grechanik
-
依托单位:
SHF: Small: Collaborative Research: Preserving Test Coverage While Achieving Data Anonymity for Database-Centric Applications
-
批准号:1017633
-
项目类别:Continuing Grant
-
资助金额:$25.0万
-
财政年份:2010
-
负责人:Mark Grechanik
-
依托单位:
III: Small: Collaborative Research: Creating and Evolving Software via Searching, Selecting and Synthesizing Relevant Source Code
-
批准号:0916139
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2009
-
负责人:Mark Grechanik
-
依托单位:
海外基金