Skip to main navigation Skip to search Skip to main content

Context-specific access control: Conforming permissions with user expectations

  • University of Michigan, Ann Arbor

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

12 Scopus citations

Abstract

Current mobile platforms take an all-or-nothing approach to assigning permissions to applications. Once a user grants an application permission to access a particular resource, the application can use that permission whenever it executes thereafter. This enables an application to access privacy sensitive resources even when they are not needed for it to perform its expected functions. In this paper, we introduce \Context-Specific Access Con- trol" (CSAC) as a design approach towards enforcing the principle of least privilege. CSAC's goal is to enable a user to ensure that, at any point in time, an application has access to those resources which she expects are needed by the ap- plication component with which she is currently interacting. We study 100 popular applications from Google Play store and find that existing applications are amenable to CSAC as most applications' use of privacy sensitive resources is limited to a small number of contexts. Furthermore, via dy- namic analysis of the 100 applications and a small-scale user study, we find that CSAC does not prohibitively increase the number of access control decisions that users need to make.

Original languageEnglish
Title of host publicationSPSM 2015 - Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, co-located with
Subtitle of host publicationCCS 2015
PublisherAssociation for Computing Machinery, Inc
Pages75-80
Number of pages6
ISBN (Electronic)9781450338196
DOIs
StatePublished - Oct 12 2015
Event5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, SPSM 2015 - Denver, United States
Duration: Oct 12 2015 → …

Publication series

NameSPSM 2015 - Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, co-located with: CCS 2015

Conference

Conference5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, SPSM 2015
Country/TerritoryUnited States
CityDenver
Period10/12/15 → …

Fingerprint

Dive into the research topics of 'Context-specific access control: Conforming permissions with user expectations'. Together they form a unique fingerprint.

Cite this