FlowFence: Practical Data Protection for Emerging IoT Application Frameworks
Explore this paper's citation graph
Summary
FlowFence is presented, a system that requires consumers of sensitive data to declare their intended data flow patterns, which it enforces with low overhead, while blocking all other undeclared flows.
- Type
- article
- Published
- 2016-08-10
- Cited by
- 299
- References
- 69
- OpenAlex
- https://openalex.org/W2474516640
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:1889404
Keywords
Computer science, Porting, Overhead (engineering), Control flow, Chaining
References
- How to Ask for Permission
- An Evaluation of the Google Chrome Extension Security Architecture
- Abstractions for Usable Information Flow Control in Aeolus
- Run-Time Enforcement of Information-Flow Properties on Android (CMU-CyLab-12-015)
- The Most Dangerous Code in the Browser
- πBox: A Platform for Privacy-Preserving Apps
- Securing Embedded User Interfaces: Android and Beyond
- Your Location has been Shared 5,398 Times!: A Field Study on Mobile App Privacy Nudging
- On the effectiveness of dynamic taint analysis for protecting against private information leaks on Android-based devices
- Scippa: system-centric IPC provenance on Android
- On lightweight mobile phone application certification
- Flexible dynamic information flow control in Haskell
- The information visualizer, an information workspace
- Maxoid: transparently confining mobile applications with custom views of state
- CRêPE: A System for Enforcing Fine-Grained Context-Related Policies on Android
- Context-Specific Access Control: Conforming Permissions With User Expectations
- Amandroid: A Precise and General Inter-component Data Flow Analysis Framework for Security Vetting of Android Apps
- Android permissions: user attention, comprehension, and behavior
- All Your IFCException Are Belong to Us
- MOSES: supporting operation modes on smartphones
Cited by
- Applying the Opacified Computation Model to Enforce Information Flow Policies in IoT Applications
- Guardian of the HAN: Thwarting Mobile Attacks on Smart-Home Devices Using OS-level Situation Awareness
- Security Implications of Permission Models in Smart-Home Application Frameworks
- Understanding IoT Security Through the Data Crystal Ball: Where We Are Now and Where We Are Going to Be
- Some Recipes Can Do More Than Spoil Your Appetite: Analyzing the Security and Privacy Risks of IFTTT Recipes
- Securing vulnerable home IoT devices with an in-hub security manager
- ContexloT: Towards Providing Contextual Integrity to Appified IoT Platforms
- FACT: Functionality-centric Access Control System for IoT Programming Frameworks
- Towards Practical Data Secrecy in Modern Operating Systems.
- Internet of Things Security Research: A Rehash of Old Ideas or New Intellectual Challenges?
- Do we need a holistic approach for the design of secure IoT systems?
- Heimdall: A Privacy-Respecting Implicit Preference Collection Framework
- Hey, you, keep away from my device: remotely implanting a virus expeller to defeat Mirai on IoT devices
- HanGuard: SDN-driven protection of smart home WiFi devices from malicious mobile apps
- End User Security and Privacy Concerns with Smart Homes
- Securing Personal IoT Platforms through Systematic Analysis and Design
- Understanding the Mirai Botnet
- From Electromyogram to Password
- SmartAuth: User-Centered Authorization for the Internet of Things
- Toward Usable Network Traffic Policies for IoT Devices in Consumer Networks
Related papers
- SmartAuth: User-Centered Authorization for the Internet of Things
- ContexloT: Towards Providing Contextual Integrity to Appified IoT Platforms
- Security Analysis of Emerging Smart Home Applications
- Smart Locks: Lessons for Securing Commodity Internet of Things Devices
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoT
- Fear and Logging in the Internet of Things
- IoT Goes Nuclear: Creating a ZigBee Chain Reaction
- Rethinking Access Control and Authentication for the Home Internet of Things (IoT)
- Decentralized Action Integrity for Trigger-Action IoT Platforms.