Polymer for Android

Building on the Polymer system designed by Bauer, Ligatti and Walker, which allowed enforcing user-defined security policies on single-threaded Java applications, this research extends Polymer to enforce policies on multiple applications, possibly distributed across several hosts. Using Android as a...

Full description

Bibliographic Details
Main Author: Bui-Nguyen, Honghanh
Format: Others
Published: Research Showcase @ CMU 2016
Online Access:http://repository.cmu.edu/theses/111
http://repository.cmu.edu/cgi/viewcontent.cgi?article=1116&context=theses
id ndltd-cmu.edu-oai-repository.cmu.edu-theses-1116
record_format oai_dc
spelling ndltd-cmu.edu-oai-repository.cmu.edu-theses-11162017-03-16T03:39:28Z Polymer for Android Bui-Nguyen, Honghanh Building on the Polymer system designed by Bauer, Ligatti and Walker, which allowed enforcing user-defined security policies on single-threaded Java applications, this research extends Polymer to enforce policies on multiple applications, possibly distributed across several hosts. Using Android as a case study, we adapted Polymer to equip each app with a monitor, and we added communication capability and central storage so that monitors can regulate interactions between apps and make decisions based on their shared state. Our central storage design also includes load-linked and store-conditional operations to support synchronization of parallel updates, and each communication module is accompanied by a non-circumvention policy designed to protect the integrity, authenticity and confidentiality properties of the channel. The non-circumvention policy can be composed with user-defined policies that involve two or more apps. To demonstrate the efficacy of the system, we implemented and tested three policies: the first prevents apps from making background calls caused by confused deputy attacks or collusion attacks; the second disallows sending background SMS messages exceeding a specified quota, and the third enforces a specified device location sampling rate among all apps on the device. 2016-05-01T07:00:00Z text application/pdf http://repository.cmu.edu/theses/111 http://repository.cmu.edu/cgi/viewcontent.cgi?article=1116&context=theses Theses Research Showcase @ CMU
collection NDLTD
format Others
sources NDLTD
description Building on the Polymer system designed by Bauer, Ligatti and Walker, which allowed enforcing user-defined security policies on single-threaded Java applications, this research extends Polymer to enforce policies on multiple applications, possibly distributed across several hosts. Using Android as a case study, we adapted Polymer to equip each app with a monitor, and we added communication capability and central storage so that monitors can regulate interactions between apps and make decisions based on their shared state. Our central storage design also includes load-linked and store-conditional operations to support synchronization of parallel updates, and each communication module is accompanied by a non-circumvention policy designed to protect the integrity, authenticity and confidentiality properties of the channel. The non-circumvention policy can be composed with user-defined policies that involve two or more apps. To demonstrate the efficacy of the system, we implemented and tested three policies: the first prevents apps from making background calls caused by confused deputy attacks or collusion attacks; the second disallows sending background SMS messages exceeding a specified quota, and the third enforces a specified device location sampling rate among all apps on the device.
author Bui-Nguyen, Honghanh
spellingShingle Bui-Nguyen, Honghanh
Polymer for Android
author_facet Bui-Nguyen, Honghanh
author_sort Bui-Nguyen, Honghanh
title Polymer for Android
title_short Polymer for Android
title_full Polymer for Android
title_fullStr Polymer for Android
title_full_unstemmed Polymer for Android
title_sort polymer for android
publisher Research Showcase @ CMU
publishDate 2016
url http://repository.cmu.edu/theses/111
http://repository.cmu.edu/cgi/viewcontent.cgi?article=1116&context=theses
work_keys_str_mv AT buinguyenhonghanh polymerforandroid
_version_ 1718421911428399104