A Middleware to Allow Fine-Grained Access Control of Twitter Applications

被引:1
作者
Buccafurri, Francesco [1 ]
Lax, Gianluca [1 ]
Nicolazzo, Serena [1 ]
Nocera, Antonino [1 ]
机构
[1] Univ Mediterranea Reggio Calabria, DIIES, Via Graziella, I-89122 Reggio Di Calabria, Italy
来源
MOBILE, SECURE, AND PROGRAMMABLE NETWORKING (MSPN 2016) | 2016年 / 10026卷
关键词
Application security; Fine-grained access control; Android; Twitter; OAuth; SECURITY; AUTHORIZATION;
D O I
10.1007/978-3-319-50463-6_14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile applications security is nowadays one of the most important topics in the field of information security, due to their pervasivity in the people's life. Among mobile applications, those that interact with social network profiles, have a great potential for development, as they intercept another powerful asset of the today cyberspace. However, one of the problems that can limit the diffusion of social network applications is the lack of fine-grained control when an application use the APIs of a social network to access a profile. For instance, in Twitter, the supported access control policy is basically on/off, so that if a (third party) application needs the right to write in a user profile, the user is enforced to grant this right with no restriction in the entire profile. This enables a large set of security threats and can make (even inexpert) users reluctant to run these applications. To overcome this problem, we propose an effective solution working for Android Twitter applications based on a middleware approach. The proposed solution enables other possible benefits, as anomaly-based malware detection leveraging API-call patterns, and it can be extended to a multiple social network scenario.
引用
收藏
页码:168 / 182
页数:15
相关论文
共 30 条
[1]  
[Anonymous], The OAuth 2.0 Authorization Framework, DOI DOI 10.17487/RFC6749
[2]  
[Anonymous], ACM COMPUT SURVEYS
[3]  
[Anonymous], 2010, Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, ASIACCS '10, DOI [10.1145/1755688.1755732, DOI 10.1145/1755688.1755732]
[4]  
[Anonymous], 2010, RFC5849
[5]  
[Anonymous], P INT C INF SYST SEC
[6]   A model to support design and development of multiple-social-network applications [J].
Buccafurri, Francesco ;
Lax, Gianluca ;
Nicolazzo, Serena ;
Nocera, Antonino .
INFORMATION SCIENCES, 2016, 331 :99-119
[7]   Comparing Twitter and Facebook user behavior: Privacy and other aspects [J].
Buccafurri, Francesco ;
Lax, Gianluca ;
Nicolazzo, Serena ;
Nocera, Antonino .
COMPUTERS IN HUMAN BEHAVIOR, 2015, 52 :87-95
[8]   A Privacy-Preserving Solution for Tracking People in Critical Environments [J].
Buccafurri, Francesco ;
Lax, Gianluca ;
Nicolazzo, Serena ;
Nocera, Antonino .
2014 38TH ANNUAL IEEE INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSACW 2014), 2014, :146-151
[9]   Driving global team formation in social networks to obtain diversity [J].
Buccafurri, Francesco ;
Lax, Gianluca ;
Nicolazzo, Serena ;
Nocera, Antonino ;
Ursino, Domenico .
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2014, 8541 :410-419
[10]  
Buccafurri F, 2013, LECT NOTES COMPUT SC, V8186, P666, DOI 10.1007/978-3-642-41033-8_84