Aware: Controlling App Access to I/O Devices on Mobile Platforms
Giuseppe Petracca, Ahmad Atamli, Yuqiong Sun, Jens Grossklags and, Trent Jaeger

TL;DR
Aware is a security framework that links user intentions with app requests to access I/O devices on mobile platforms, significantly reducing unauthorized access and social engineering attacks with minimal performance impact.
Contribution
It introduces a novel binding mechanism between user interactions and I/O device access requests, enhancing mobile device security against malicious apps and social engineering.
Findings
Increased user ability to detect I/O misuse from 18% to 82%.
System effectively blocks all tested I/O attacks without user consent.
Minimal performance overhead of 4.79%.
Abstract
Smartphones' cameras, microphones, and device displays enable users to capture and view memorable moments of their lives. However, adversaries can trick users into authorizing malicious apps that exploit weaknesses in current mobile platforms to misuse such on-board I/O devices to stealthily capture photos, videos, and screen content without the users' consent. Contemporary mobile operating systems fail to prevent such misuse of I/O devices by authorized apps due to lack of binding between users' interactions and accesses to I/O devices performed by these apps. In this paper, we propose Aware, a security framework for authorizing app requests to perform operations using I/O devices, which binds app requests with user intentions to make all uses of certain I/O devices explicit. We evaluate our defense mechanisms through laboratory-based experimentation and a user study, involving 74…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection · User Authentication and Security Systems
