CISPA
Browse

File(s) not publicly available

Why does this App need this Data? Automatic Tightening of Resource Access

conference contribution
posted on 2023-11-29, 18:10 authored by Nataniel Pereira Borges Jr., Andreas ZellerAndreas Zeller
On mobile operating systems, apps may access resources that are not be needed for their primary functionality. Which are the resources an app actually needs for its core functionality? And what happens if we deny access to other resources? Using a test generator for user interaction, we systematically explore app behavior under varied resource constraints and determine the impact of access restrictions, yielding a minimal set of required privileges for each app and functionality. In our proof of concept on Android apps, our TIARA prototype could block up to 69% of resource accesses while retaining all previously explored functionality.

History

Preferred Citation

Nataniel Jr. and Andreas Zeller. Why does this App need this Data? Automatic Tightening of Resource Access. In: International Conference on Software Testing, Verification and Validation (ICST). 2019.

Primary Research Area

  • Secure Connected and Mobile Systems

Name of Conference

International Conference on Software Testing, Verification and Validation (ICST)

Legacy Posted Date

2019-04-30

Open Access Type

  • Hybrid

BibTeX

@inproceedings{cispa_all_2882, title = "Why does this App need this Data? Automatic Tightening of Resource Access", author = "Jr., Nataniel Pereira Borges and Zeller, Andreas", booktitle="{International Conference on Software Testing, Verification and Validation (ICST)}", year="2019", }

Usage metrics

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC