Yaser Mowafi, D. E. D. I. Abou-Tair, Tareq Al-Aqarbeh, M. Abilov, V. Dmitriyev, J. Gómez
{"title":"A Context-aware Adaptive Security Framework for Mobile Applications","authors":"Yaser Mowafi, D. E. D. I. Abou-Tair, Tareq Al-Aqarbeh, M. Abilov, V. Dmitriyev, J. Gómez","doi":"10.4108/ICST.ICCASA.2014.257495","DOIUrl":null,"url":null,"abstract":"Mobile devices currently offer many value-added applications and services such as messaging, navigation, social networking, finance, and entertainment. As these mobile applications have access to users' personal information and are capable of gathering and transmitting trust sensitive information, posing security and privacy risks. In this paper, we propose a context-aware adaptive security framework for eliciting users' context information and adapting this information with mobile applications' network access control mechanism. The framework enforces the execution of mobile applications inside security incubators to control the communication between mobile applications and mobile device resources. Applications' access requests are analyzed based on user's context information collected from the mobile device sensors and the application security configuration.","PeriodicalId":426100,"journal":{"name":"International Conference on Context-Aware Systems and Applications","volume":"138 4","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-10-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Conference on Context-Aware Systems and Applications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4108/ICST.ICCASA.2014.257495","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14
Abstract
Mobile devices currently offer many value-added applications and services such as messaging, navigation, social networking, finance, and entertainment. As these mobile applications have access to users' personal information and are capable of gathering and transmitting trust sensitive information, posing security and privacy risks. In this paper, we propose a context-aware adaptive security framework for eliciting users' context information and adapting this information with mobile applications' network access control mechanism. The framework enforces the execution of mobile applications inside security incubators to control the communication between mobile applications and mobile device resources. Applications' access requests are analyzed based on user's context information collected from the mobile device sensors and the application security configuration.