Securing Embedded User Interfaces: Android and Beyond.

SEC'13: Proceedings of the 22nd USENIX conference on Security(2013)

引用 40|浏览45
暂无评分
摘要
Web and smartphone applications commonly embed third-party user interfaces like advertisements and social media widgets. However, this capability comes with security implications, both for the embedded interfaces and the host page or application. While browsers have evolved over time to address many of these issues, mobile systems like Android--which do not yet support true cross-application interface embedding--present an opportunity to redesign support for secure embedded user interfaces from scratch. In this paper, we explore the requirements for a system to support secure embedded user interfaces by systematically analyzing existing systems like browsers, smartphones, and research systems. We describe our experience modifying Android to support secure interface embedding and evaluate our implementation using case studies that rely on embedded interfaces, such as advertisement libraries, Facebook social plugins (e.g., the "Like" button), and access control gadgets. We provide concrete techniques and reflect on lessons learned for secure embedded user interfaces.
更多
查看译文
关键词
secure embedded user interface,embedded interface,secure interface embedding,third-party user interface,Facebook social plugins,social media widget,true cross-application interface embedding,access control gadget,advertisement library,case study
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要