Short paper: rethinking permissions for mobile web apps: barriers and the road ahead

Chaitrali Amrutkar, Patrick Traynor
{"title":"Short paper: rethinking permissions for mobile web apps: barriers and the road ahead","authors":"Chaitrali Amrutkar, Patrick Traynor","doi":"10.1145/2381934.2381939","DOIUrl":null,"url":null,"abstract":"The distinction between mobile applications built for specific platforms and that run in mobile browsers is increasingly being blurred. As HTML5 becomes universally deployed and mobile web apps directly take advantage of device features such as the camera, microphone and geolocation information, this difference will vanish almost entirely. In spite of this increasing similarity, the permission systems protecting mobile device resources for native1 and web apps are dramatically different. In this position paper, we argue that the increasing indistinguishability between such apps coupled with the dynamic nature of mobile web apps calls for reconsidering the current permission model for mobile web apps. We first discuss factors associated with securing mobile web apps in comparison to traditional apps. We then propose a mechanism that presents a holistic view of the permissions required by a web app and provides a simple, single-stop permission management process. We then briefly discuss issues surrounding the use and deployment of this technique. In so doing, we argue that in the absence of an in-cloud security model for mobile web apps, client side defenses are limited. Our model can provide users with a better chance of making informed security decisions and may also aid researchers in assessing security of mobile web apps.","PeriodicalId":213305,"journal":{"name":"Security and Privacy in Smartphones and Mobile Devices","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-10-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Security and Privacy in Smartphones and Mobile Devices","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2381934.2381939","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

The distinction between mobile applications built for specific platforms and that run in mobile browsers is increasingly being blurred. As HTML5 becomes universally deployed and mobile web apps directly take advantage of device features such as the camera, microphone and geolocation information, this difference will vanish almost entirely. In spite of this increasing similarity, the permission systems protecting mobile device resources for native1 and web apps are dramatically different. In this position paper, we argue that the increasing indistinguishability between such apps coupled with the dynamic nature of mobile web apps calls for reconsidering the current permission model for mobile web apps. We first discuss factors associated with securing mobile web apps in comparison to traditional apps. We then propose a mechanism that presents a holistic view of the permissions required by a web app and provides a simple, single-stop permission management process. We then briefly discuss issues surrounding the use and deployment of this technique. In so doing, we argue that in the absence of an in-cloud security model for mobile web apps, client side defenses are limited. Our model can provide users with a better chance of making informed security decisions and may also aid researchers in assessing security of mobile web apps.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
简而言之:重新思考移动网络应用的许可:障碍和前进的道路
为特定平台构建的移动应用程序和在移动浏览器中运行的移动应用程序之间的区别越来越模糊。随着HTML5的普及,以及移动网络应用直接利用摄像头、麦克风和地理位置信息等设备功能,这种差异将几乎完全消失。尽管有越来越多的相似之处,但保护原生应用程序和web应用程序的移动设备资源的权限系统却截然不同。在这篇立场论文中,我们认为这些应用程序之间日益增加的不可区分性,加上移动web应用程序的动态特性,要求重新考虑当前移动web应用程序的权限模型。我们首先讨论了与传统应用相比,保护移动网页应用的相关因素。然后,我们提出了一种机制,该机制提供了web应用程序所需的权限的整体视图,并提供了一个简单的,单次停止的权限管理过程。然后,我们简要讨论围绕该技术的使用和部署的问题。在这样做的过程中,我们认为在移动web应用程序缺乏云内安全模型的情况下,客户端防御是有限的。我们的模型可以为用户提供更好的机会做出明智的安全决策,也可以帮助研究人员评估移动网络应用程序的安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Sound and precise malware analysis for android via pushdown reachability and entry-point saturation Deadbolt: locking down android disk encryption Secure enrollment and practical migration for mobile trusted execution environments Passwords and interfaces: towards creating stronger passwords by using mobile phone handsets Please slow down!: the impact on tor performance from mobility
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1