Skip to main navigation Skip to search Skip to main content

A middleware to allow fine-grained access control of Twitter applications

  • F. Buccafurri
  • , G. Lax
  • , SERENA NICOLAZZO
  • , A. Nocera

Research output: Contribution to conferencePaperpeer-review

Abstract

Mobile applications security is nowadays one of the most important topics in the field of information security, due to their pervasivity in the people’s life. Among mobile applications, those that interact with social network profiles, have a great potential for development, as they intercept another powerful asset of the today cyberspace. However, one of the problems that can limit the diffusion of social network applications is the lack of fine-grained control when an application use the APIs of a social network to access a profile. For instance, in Twitter, the supported access control policy is basically on/off, so that if a (third party) application needs the right to write in a user profile, the user is enforced to grant this right with no restriction in the entire profile. This enables a large set of security threats and can make (even inexpert) users reluctant to run these applications. To overcome this problem, we propose an effective solution working for Android Twitter applications based on a middleware approach. The proposed solution enables other possible benefits, as anomaly-based malware detection leveraging API-call patterns, and it can be extended to a multiple social network scenario.
Original languageEnglish
Pages168-182
Number of pages15
DOIs
Publication statusPublished - 2016
EventInternational Conference on Mobile, Secure, and Programmable Networking - Paris, France
Duration: 1 Jan 2016 → …

Conference

ConferenceInternational Conference on Mobile, Secure, and Programmable Networking
CityParis, France
Period1/01/16 → …

Keywords

  • Android
  • Application security
  • Fine-grained access control
  • OAuth
  • Twitter

Fingerprint

Dive into the research topics of 'A middleware to allow fine-grained access control of Twitter applications'. Together they form a unique fingerprint.

Cite this