(2019) Why does this App need this Data? Automatic Tightening of Resource Access.
In: 2019 IEEE 12th International Conference on Software Testing, Verification and Validation (ICST).
Conference:
ICST International Conference on Software Testing, Verification and Validation
Abstract
On mobile operating systems, apps may access resources that are not be needed for their primary functionality. Which are the resources an app actually needs for its core functionality? And what happens if we deny access to other resources? Using a test generator for user interaction, we systematically explore app behavior under varied resource constraints and determine the impact of access restrictions, yielding a minimal set of required privileges for each app and functionality. In our proof of concept on Android apps, our TIARA prototype could block up to 69% of resource accesses while retaining all previously explored functionality.
Item Type: | Conference or Workshop Item (A Paper) (Paper) |
---|---|
Divisions: | Andreas Zeller (Software Engineering, ST) |
Conference: | ICST International Conference on Software Testing, Verification and Validation |
Depositing User: | Nataniel Pereira Borges Jr. |
Date Deposited: | 30 Apr 2019 13:02 |
Last Modified: | 17 Oct 2022 10:20 |
Primary Research Area: | NRA4: Secure Mobile and Autonomous Systems |
URI: | https://publications.cispa.saarland/id/eprint/2882 |
Actions
Actions (login required)
View Item |