A Trusted Ecosystem For Android Applications Based On Context-Aware Access Control

Abstract

Private data stored on smartphones is a precious target for malware attacks. A constantly changing environment, e.g. switching network connections, can cause unpredictable threats, and require an adaptive approach to access control. Context-based access control is using dynamic environmental information, including it into access decisions. We propose an “ecosystem-in-an-ecosystem” which acts as a secure container for trusted software aiming at enterprise scenarios where users are allowed to use private devices. We have implemented a proof-of-concept prototype for an access control framework that processes changes to low-level sensors and semantically enriches them, adapting access control policies to the current context. This allows the user or the administrator to maintain fine-grained control over resource usage by compliant applications. Hence, resources local to the trusted container remain under control of the enterprise policy. Our results show that context-based access control can be done on smartphones without major performance impact.

@inproceedings{malware2012herpich,
author = {Markus Herpich and Leonid Batyuk and Seyit Ahmet Camtepe and Sahin Albayrak},
title = {A Trusted Ecosystem For Android Applications Based On Context-Aware Access Control},
booktitle = {7th International Conference on Malicious and Unwanted Software (Malware 2012)},
year = {2012}
}
Authors:
Markus Herpich, Leonid Batyuk, Seyit Ahmet Camtepe, Sahin Albayrak
Category:
Conference Paper
Year:
2012
Location:
7th International Conference on Malicious and Unwanted Software (Malware 2012)