MuTent: Dynamic Android Intent Protection with Ownership-Based Key Distribution and Security Contracts

dc.contributor.authorDuraisamy Soundrapandian, Pradeep Kumar
dc.contributor.authorBao, Tiffany
dc.contributor.authorBaek, Jaejong
dc.contributor.authorShoshitaishvili, Yan
dc.contributor.authorDoupé, Adam
dc.contributor.authorWang, Ruoyu
dc.contributor.authorAhn, Gail-Joon
dc.date.accessioned2020-12-24T20:30:27Z
dc.date.available2020-12-24T20:30:27Z
dc.date.issued2021-01-05
dc.description.abstractIntents are the plain-text based message object used for ICC by the Android framework. Hence the framework essentially lacks an inbuilt security mechanism to protect the visibility, accessibility, and integrity of Intent's data that facilitates adversaries to intercept or manipulate the data. In this work, we investigate the Intent protection mechanism and propose a security-enhanced Intent library MuTent that allows Android apps to securely exchange sensitive data during ICC. Differently from the existing mechanism, MuTent provides accessibility and visibility of Intent data by validating the receiver's capability and provides integrity by using encryption and the Arc security contract code. Especially, ICC is initiated by exchanging MuTent and follows a novel ownership-based key distribution model, that restricts the malware apps without permission from deciphering data. Through the evaluation, we show that MuTent can improve the security for popular Android apps with minimal performance overheads, demonstrated using F-Droid apps.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2021.869
dc.identifier.isbn978-0-9981331-4-0
dc.identifier.urihttp://hdl.handle.net/10125/71490
dc.language.isoEnglish
dc.relation.ispartofProceedings of the 54th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectSoftware Development for Mobile Devices, the Internet-of-Things, and Cyber-Physical Systems
dc.subjectencryption
dc.subjectintent leak
dc.subjectmutation attack
dc.subjectownership-based key generation and distribution
dc.subjectownership types
dc.subjectsecurity contracts
dc.titleMuTent: Dynamic Android Intent Protection with Ownership-Based Key Distribution and Security Contracts
prism.startingpage7217

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0705.pdf
Size:
1.24 MB
Format:
Adobe Portable Document Format