Security for mobile devices is a problem of capital importance, especially due to new threats coming from malicious applications. This has been proved by the increasing interest of the research community on the topic of security on mobile devices. Several security solutions have been recently proposed, to address the uprising threats coming from malicious applications. However, several mechanisms may result not flexible enough, hard to apply, or too coarse grained, e.g. several critics have been raised against the Android permission system. We argue that, it is possible to obtain more flexible security tools and finer grained security requirements by introducing probability measurements. In this paper we discuss how to introduce probabilistic clauses into the Security-by-Contract and the Security-by-Contract-with-Trust frameworks, revising the main building blocks and providing tools to write probabilistic contracts and policies. A proof-of-concept implementation on Android system has also been presented. © 2014 Springer-Verlag Berlin Heidelberg.
CITATION STYLE
Dini, G., Martinelli, F., Matteucci, I., Saracino, A., & Sgandurra, D. (2014). Introducing probabilities in contract-based approaches for mobile application security. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 8247 LNCS, pp. 284–299). Springer Verlag. https://doi.org/10.1007/978-3-642-54568-9_18
Mendeley helps you to discover research relevant for your work.