Skip to feedback

Award Abstract # 1318722
TWC: Small: Discovering and Restricting Undesirable Information Flows Between Multiple Spheres of Activities

NSF Org: CNS
Division Of Computer and Network Systems
Recipient: REGENTS OF THE UNIVERSITY OF MICHIGAN
Initial Amendment Date: August 19, 2013
Latest Amendment Date: August 19, 2013
Award Number: 1318722
Award Instrument: Standard Grant
Program Manager: Fen Zhao
CNS
 Division Of Computer and Network Systems
CSE
 Directorate for Computer and Information Science and Engineering
Start Date: September 1, 2013
End Date: August 31, 2017 (Estimated)
Total Intended Award Amount: $488,744.00
Total Awarded Amount to Date: $488,744.00
Funds Obligated to Date: FY 2013 = $488,744.00
History of Investigator:
  • Atul Prakash (Principal Investigator)
    aprakash@umich.edu
Recipient Sponsored Research Office: Regents of the University of Michigan - Ann Arbor
1109 GEDDES AVE STE 3300
ANN ARBOR
MI  US  48109-1015
(734)763-6438
Sponsor Congressional District: 06
Primary Place of Performance: University of Michigan Ann Arbor
2260 Hayward Street
Ann Arbor
MI  US  48109-2121
Primary Place of Performance
Congressional District:
06
Unique Entity Identifier (UEI): GNJ7BBP73WE9
Parent UEI:
NSF Program(s): Secure &Trustworthy Cyberspace
Primary Program Source: 01001314DB NSF RESEARCH & RELATED ACTIVIT
Program Reference Code(s): 7434, 7923
Program Element Code(s): 806000
Award Agency Code: 4900
Fund Agency Code: 4900
Assistance Listing Number(s): 47.070

ABSTRACT

Loss of personal data or leakage of corporate data via apps on mobile devices poses a significant risk to users. It can have both a huge personal and financial cost. This work is designing new novel techniques to help reduce the risks for end-users who use a single device for multiple spheres of activity. Getting security right when a single device is used for multiple spheres of activity is a major research challenge, with unforeseen information flows between various subsystems that are currently difficult to control. This project is developing mechanisms to better manage flows between apps on a mobile device so that users are able to compartmentalize different spheres of activity, such as work and personal use.

Broader impact: This research benefits both end-users who are concerned about the privacy of their data on mobile devices as well as businesses who wish to permit use of mobile devices for improving efficiency of their operations but are concerned about resulting security risks. Graduate and undergraduate students are trained in the area of security and privacy of information on mobile devices.

PUBLICATIONS PRODUCED AS A RESULT OF THIS RESEARCH

Note:  When clicking on a Digital Object Identifier (DOI) number, you will be taken to an external site maintained by the publisher. Some full text articles may not yet be available without a charge during the embargo (administrative interval).

Some links on this page may take you to non-federal websites. Their policies may differ from this site.

(Showing: 1 - 10 of 11)
Amir Rahmati and Earlence Fernandes and Atul Prakash "Applying the Opacified Computation Model to Enforce Information Flow Policies in IoT Applications" {IEEE} Cybersecurity Development, SecDev 2016, Boston, MA, USA, November 3-4, 2016 , 2016 , p.88--93 10.1109/SecDev.2016.031
Amir Rahmati and Earlence Fernandes and Kevin Eykholt and Xinheng Chen and Atul Prakash "Heimdall: {A} Privacy-Respecting Implicit Preference Collection Framework" Proceedings of the 15th Annual International Conference on Mobile Systems, Applications, and Services, MobiSys'17, Niagara Falls, NY, USA, June 19-23, 2017 , 2017 , p.453--463 10.1145/3081333.3081334
Earlence Fernandes and Ajit Aluri and Alexander Crowell and Atul Prakash "Decomposable Trust for Android Applications" 45th Annual {IEEE/IFIP} International Conference on Dependable Systems and Networks, {DSN} 2015, Rio de Janeiro, Brazil, June 22-25, 2015 , 2015 , p.343--354 10.1109/DSN.2015.15
Earlence Fernandes and Jaeyeon Jung and Atul Prakash "Security Analysis of Emerging Smart Home Applications" {IEEE} Symposium on Security and Privacy, {SP} 2016, San Jose, CA, USA, May 22-26, 2016 , 2016 , p.636--654 10.1109/SP.2016.44
Earlence Fernandes and Justin Paupore and Amir Rahmati and Daniel Simionato and Mauro Conti and Atul Prakash "FlowFence: Practical Data Protection for Emerging IoT Application Frameworks" 25th {USENIX} Security Symposium, {USENIX} Security 16, Austin, TX, USA, August 10-12, 2016. , 2016 , p.531--548
Earlence Fernandes and Qi Alfred Chen and Justin Paupore and Georg Essl and J. Alex Halderman and Zhuoqing Morley Mao and Atul Prakash "Android {UI} Deception Revisited: Attacks and Defenses" Financial Cryptography and Data Security - 20th International Conference, {FC} 2016, Christ Church, Barbados, February 22-26, 2016, Revised Selected Papers , 2016 , p.41--59 10.1007/978-3-662-54970-4_3
Earlence Fernandes, Jaeyeon Jung, and Atul Prakash "Security Analysis of Emerging Smart Home Applications" In Proceedings of 37th IEEE Symposium on Security and Privacy, May 2016 , 2016
Earlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato, Mauro Conti, and Atul Prakash "FlowFence: Practical Data Protection for Emerging IoT Application Frameworks" In Proceedings of the 25th USENIX Security Symposium, August 2016 , 2016
Earlence Fernandes, Qi Alfred Chen, Justin Paupore,Georg Essl, J. Alex Halderman, Z. Morley Mao, Atul Prakash "Android UI Deception Revisited:Attacks and Defenses" Financial Cryptography and Data Security , 2016
Rahmati, Amir and Fernandes, Earlence and Eykholt, Kevin and Chen, Xinheng and Prakash, Atul "Heimdall: A Privacy-Respecting Implicit Preference Collection Framework" Proceedings of the 15th Annual International Conference on Mobile Systems, Applications, and Services (MobiSys) , 2017 10.1145/3081333.3081334 Citation Details
Yunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati, Earlence Fernandes, Z. Morley Mao, and Atul Prakash "ContexIoT: Towards Providing Contextual Integrity to Appified IoT Platforms" 21st Network and Distributed Security Symposium (NDSS) , 2017
(Showing: 1 - 10 of 11)

PROJECT OUTCOMES REPORT

Disclaimer

This Project Outcomes Report for the General Public is displayed verbatim as submitted by the Principal Investigator (PI) for this award. Any opinions, findings, and conclusions or recommendations expressed in this Report are those of the PI and do not necessarily reflect the views of the National Science Foundation; NSF has not approved or endorsed its content.

A major goal of the project was to design mechanisms for protecting sensitive information on mobile devices. 

Intellectual Merits: The work led to the (1) development of a sandboxing mechanism for applications on Android to reduce the risks of sensitive information leakage from privilege escalation attacks;(2) development of a robust user-interface mechanism to help users detect phishing attacks from malicious apps; (3) over-privilege analysis of software stacks for the emerging domain of Internet ofThings to help assess security and privacy risks; (4) development of a mechanism called FlowFence to prevent undesirable information flows in mobile and Internet of Things applications; and (5) development of an operating systems mechanism called Heimdall to improve the quality of recommendations in mobile apps, while limiting the security and privacy risks due to use of implicitly collected information such as user's GPS data. The results were disseminated through publications at top-tier academic security venues including UsenixSecurity Symposium, IEEE Symposium on Security and Privacy, and ACMMobiSys.


Broader Impacts: Applications on sensor-rich smartphones that interface with social networks and emerging Internet of Things systems can introduce significant security and privacy risks. This research helped identify and address some of those risks. The research grant supported the research of two Ph.D. graduates in the computer security area. Both students have interacted with research labs in industry and are planning to pursue academic careers to help educate future computer science students. The results from the research have been broadly disseminated via both research publications and ourgroup's web site. The results from research on security of Internet of Things applications has attracted attention in the press, helping to increase awareness of security and privacy considerations with the use of connected devices and emerging software stacks to manage them.


Last Modified: 11/26/2017
Modified by: Atul Prakash

Please report errors in award information by writing to: awardsearch@nsf.gov.

Print this page

Back to Top of page