{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/105929"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/105929","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Practical least privilege for cross-origin interactions on mobile operating systems","abstract":"Mobile operating systems (i.e., mobile platforms) favor flexibility and re-usability as design principles and provide mobile applications with channels for establishing cross-origin interactions in an effort to realize these principles. Under this cross-origin scheme, applications accomplish tasks collaboratively with other principals, such as the web, other applications, and system components, by relying on them for certain functionality and data, considerably saving platform resources as well as the programming efforts of application developers. While clearly helping to provide a captivating mobile experience, this rich set of interactions within mobile platforms unfortunately also create significant attack vectors and pose notable security risks that need to be carefully taken into account to ensure the security of the platform. In this thesis, we focus on the security of cross-origin interaction channels on mobile operating systems. We choose Android as a use case due to its popularity and open source and show that cross-origin interactions constitute a significant impediment to establishing least privilege on Android. More specifically, we show that there are severe issues in the security mechanisms that are put in place by Android or even a lack of adequate mechanisms to protect these interactions, which enable adversaries to stealthily obtain sensitive user data, high-risk platform resources, and application functionalities. We demonstrate the severity of these vulnerabilities by our measurement studies and showcases of exploits on popular real-world applications with millions of downloads on Google Play and show that a majority of Android users are rendered vulnerable due to these critical issues. As a remedy, we propose practical designs that strive to make Android more robust and secure by addressing the problems with cross-origin channels in a systematic, effective, and efficient manner. In particular, we show that mobile applications that utilize embedded web browsers are under the risk of inadvertently exposing critical resources to untrusted web domains and we propose a systematic and practical access control mechanism to address this issue. Additionally, we disclose serious vulnerabilities in Android's permission framework that put inter-process communication and platform resources at severe risk and we redesign Android permissions to systematically resolve the issues. Finally, we present new attacks on Android's runtime permissions which proves that this new permission model cannot satisfy its key security guarantees due to design issues and vulnerabilities, jeopardizing the security of platform resources. We discuss the current approach taken by Android to mitigate these issues and demonstrate how this mechanism, although seemingly an ideal solution, is still intrinsically broken due to the existing vulnerabilities that we discovered. All in all, this thesis aims to identify issues that threaten least privilege on mobile platforms and strives to provide practical mitigation solutions to resolve such issues. Our work has influenced the design and implementation of some of the critical security mechanisms in Android and has consequently led to changes in the official Android releases by Google. Even though we used Android as a use case here, the issues we disclosed in this thesis can also be encountered on other mobile platforms that utilize cross-origin interactions and our methodologies and designs go beyond Android to the design of mobile operating systems more generally.","abstract_html":"Mobile operating systems (i.e., mobile platforms) favor flexibility and re-usability as design principles and provide mobile applications with channels for establishing cross-origin interactions in an effort to realize these principles. Under this cross-origin scheme, applications accomplish tasks collaboratively with other principals, such as the web, other applications, and system components, by relying on them for certain functionality and data, considerably saving platform resources as well as the programming efforts of application developers. While clearly helping to provide a captivating mobile experience, this rich set of interactions within mobile platforms unfortunately also create significant attack vectors and pose notable security risks that need to be carefully taken into account to ensure the security of the platform. In this thesis, we focus on the security of cross-origin interaction channels on mobile operating systems. We choose Android as a use case due to its popularity and open source and show that cross-origin interactions constitute a significant impediment to establishing least privilege on Android. More specifically, we show that there are severe issues in the security mechanisms that are put in place by Android or even a lack of adequate mechanisms to protect these interactions, which enable adversaries to stealthily obtain sensitive user data, high-risk platform resources, and application functionalities. We demonstrate the severity of these vulnerabilities by our measurement studies and showcases of exploits on popular real-world applications with millions of downloads on Google Play and show that a majority of Android users are rendered vulnerable due to these critical issues. As a remedy, we propose practical designs that strive to make Android more robust and secure by addressing the problems with cross-origin channels in a systematic, effective, and efficient manner. In particular, we show that mobile applications that utilize embedded web browsers are under the risk of inadvertently exposing critical resources to untrusted web domains and we propose a systematic and practical access control mechanism to address this issue. Additionally, we disclose serious vulnerabilities in Android&#x27;s permission framework that put inter-process communication and platform resources at severe risk and we redesign Android permissions to systematically resolve the issues. Finally, we present new attacks on Android&#x27;s runtime permissions which proves that this new permission model cannot satisfy its key security guarantees due to design issues and vulnerabilities, jeopardizing the security of platform resources. We discuss the current approach taken by Android to mitigate these issues and demonstrate how this mechanism, although seemingly an ideal solution, is still intrinsically broken due to the existing vulnerabilities that we discovered. All in all, this thesis aims to identify issues that threaten least privilege on mobile platforms and strives to provide practical mitigation solutions to resolve such issues. Our work has influenced the design and implementation of some of the critical security mechanisms in Android and has consequently led to changes in the official Android releases by Google. Even though we used Android as a use case here, the issues we disclosed in this thesis can also be encountered on other mobile platforms that utilize cross-origin interactions and our methodologies and designs go beyond Android to the design of mobile operating systems more generally.","abstract_has_math":false,"creators":["Tuncay, Güliz Seray"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Gunter, Carl A.","Xie, Tao","Bates, Adam","Jana, Suman"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2019,"date_issued":"2019-11-26T20:59:44Z","date_published":"2019-11-26T20:59:44Z","updated_at":"2026-07-22T22:24:45Z","subjects":["mobile security, cross-origin interactions, access control, Android"],"languages":["en"],"rights":["Copyright 2019 Güliz Seray Tuncay"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/105929","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Gunter, Carl A.","Xie, Tao","Bates, Adam","Jana, Suman"]},{"key":"dc:creator","label":"Author","values":["Tuncay, Güliz Seray"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2019-11-26T20:59:44Z","2019-07-10","2019-08"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["mobile security, cross-origin interactions, access control, Android"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2019 Güliz Seray Tuncay"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/105929"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Mobile operating systems (i.e., mobile platforms) favor flexibility and re-usability as design principles and provide mobile applications with channels for establishing cross-origin interactions in an effort to realize these principles. Under this cross-origin scheme, applications accomplish tasks collaboratively with other principals, such as the web, other applications, and system components, by relying on them for certain functionality and data, considerably saving platform resources as well as the programming efforts of application developers. While clearly helping to provide a captivating mobile experience, this rich set of interactions within mobile platforms unfortunately also create significant attack vectors and pose notable security risks that need to be carefully taken into account to ensure the security of the platform. In this thesis, we focus on the security of cross-origin interaction channels on mobile operating systems. We choose Android as a use case due to its popularity and open source and show that cross-origin interactions constitute a significant impediment to establishing least privilege on Android. More specifically, we show that there are severe issues in the security mechanisms that are put in place by Android or even a lack of adequate mechanisms to protect these interactions, which enable adversaries to stealthily obtain sensitive user data, high-risk platform resources, and application functionalities. We demonstrate the severity of these vulnerabilities by our measurement studies and showcases of exploits on popular real-world applications with millions of downloads on Google Play and show that a majority of Android users are rendered vulnerable due to these critical issues. As a remedy, we propose practical designs that strive to make Android more robust and secure by addressing the problems with cross-origin channels in a systematic, effective, and efficient manner. In particular, we show that mobile applications that utilize embedded web browsers are under the risk of inadvertently exposing critical resources to untrusted web domains and we propose a systematic and practical access control mechanism to address this issue. Additionally, we disclose serious vulnerabilities in Android's permission framework that put inter-process communication and platform resources at severe risk and we redesign Android permissions to systematically resolve the issues. Finally, we present new attacks on Android's runtime permissions which proves that this new permission model cannot satisfy its key security guarantees due to design issues and vulnerabilities, jeopardizing the security of platform resources. We discuss the current approach taken by Android to mitigate these issues and demonstrate how this mechanism, although seemingly an ideal solution, is still intrinsically broken due to the existing vulnerabilities that we discovered. All in all, this thesis aims to identify issues that threaten least privilege on mobile platforms and strives to provide practical mitigation solutions to resolve such issues. Our work has influenced the design and implementation of some of the critical security mechanisms in Android and has consequently led to changes in the official Android releases by Google. Even though we used Android as a use case here, the issues we disclosed in this thesis can also be encountered on other mobile platforms that utilize cross-origin interactions and our methodologies and designs go beyond Android to the design of mobile operating systems more generally.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2021-08-01","The student, Guliz Tuncay, accepted the attached license on 2019-07-10 at 14:16.","The student, Guliz Tuncay, submitted this Dissertation for approval on 2019-07-10 at 14:33.","This Dissertation was approved for publication on 2019-07-10 at 16:04.","DSpace SAF Submission Ingestion Package generated from Vireo submission #14248 on 2019-11-26 at 14:03:41","Made available in DSpace on 2019-11-26T20:59:44Z (GMT). No. of bitstreams: 5 TUNCAY-DISSERTATION-2019.pdf: 2434972 bytes, checksum: db6fc3ccb31e3150fdb5f9f5978f9890 (MD5) UIUC Thesis.zip: 8003616 bytes, checksum: 2075ac203dc5affe0148e5ba7ca72885 (MD5) LICENSE.txt: 4209 bytes, checksum: f984b9c329e6358d2015ccfa0d43c18a (MD5) Tuncay Permission letter 2.pdf: 957084 bytes, checksum: a44a5fee7337cd7a607dbda966c913fd (MD5) Tuncay Permission letter.pdf: 19532 bytes, checksum: 5c64e90218dbaf18e11e50dc4ab1110e (MD5) Previous issue date: 2019-07-10","Embargo set by: Seth Robbins for item 113076 Lift date: 2021-11-26T20:59:54Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Open Restriction set for Item 113076 on 2020-10-30T15:38:01Z with date null by astein@illinois.edu.","Open Restriction set for Item 113076 on 2020-10-30T15:38:03Z with date null by astein@illinois.edu.","Limited Restriction set for Item 113076 on 2020-10-30T15:43:36Z with date 2021-08-01 by astein@illinois.edu.","Limited Restriction set for Item 113076 on 2020-10-30T15:43:39Z with date 2021-08-01 by astein@illinois.edu.","Open Restriction set for Item 113076 on 2020-12-17T14:13:57Z with date null by madinag@illinois.edu.","Open Restriction set for Item 113076 on 2020-12-17T14:14:03Z with date null by madinag@illinois.edu.","Open"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Practical least privilege for cross-origin interactions on mobile operating systems"]}]}],"canonical_facts":{"dc:contributor":["Gunter, Carl A.","Xie, Tao","Bates, Adam","Jana, Suman"],"dc:creator":["Tuncay, Güliz Seray"],"dc:date":["2019-11-26T20:59:44Z","2019-07-10","2019-08"],"dc:description":["Mobile operating systems (i.e., mobile platforms) favor flexibility and re-usability as design principles and provide mobile applications with channels for establishing cross-origin interactions in an effort to realize these principles. Under this cross-origin scheme, applications accomplish tasks collaboratively with other principals, such as the web, other applications, and system components, by relying on them for certain functionality and data, considerably saving platform resources as well as the programming efforts of application developers. While clearly helping to provide a captivating mobile experience, this rich set of interactions within mobile platforms unfortunately also create significant attack vectors and pose notable security risks that need to be carefully taken into account to ensure the security of the platform. In this thesis, we focus on the security of cross-origin interaction channels on mobile operating systems. We choose Android as a use case due to its popularity and open source and show that cross-origin interactions constitute a significant impediment to establishing least privilege on Android. More specifically, we show that there are severe issues in the security mechanisms that are put in place by Android or even a lack of adequate mechanisms to protect these interactions, which enable adversaries to stealthily obtain sensitive user data, high-risk platform resources, and application functionalities. We demonstrate the severity of these vulnerabilities by our measurement studies and showcases of exploits on popular real-world applications with millions of downloads on Google Play and show that a majority of Android users are rendered vulnerable due to these critical issues. As a remedy, we propose practical designs that strive to make Android more robust and secure by addressing the problems with cross-origin channels in a systematic, effective, and efficient manner. In particular, we show that mobile applications that utilize embedded web browsers are under the risk of inadvertently exposing critical resources to untrusted web domains and we propose a systematic and practical access control mechanism to address this issue. Additionally, we disclose serious vulnerabilities in Android's permission framework that put inter-process communication and platform resources at severe risk and we redesign Android permissions to systematically resolve the issues. Finally, we present new attacks on Android's runtime permissions which proves that this new permission model cannot satisfy its key security guarantees due to design issues and vulnerabilities, jeopardizing the security of platform resources. We discuss the current approach taken by Android to mitigate these issues and demonstrate how this mechanism, although seemingly an ideal solution, is still intrinsically broken due to the existing vulnerabilities that we discovered. All in all, this thesis aims to identify issues that threaten least privilege on mobile platforms and strives to provide practical mitigation solutions to resolve such issues. Our work has influenced the design and implementation of some of the critical security mechanisms in Android and has consequently led to changes in the official Android releases by Google. Even though we used Android as a use case here, the issues we disclosed in this thesis can also be encountered on other mobile platforms that utilize cross-origin interactions and our methodologies and designs go beyond Android to the design of mobile operating systems more generally.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2021-08-01","The student, Guliz Tuncay, accepted the attached license on 2019-07-10 at 14:16.","The student, Guliz Tuncay, submitted this Dissertation for approval on 2019-07-10 at 14:33.","This Dissertation was approved for publication on 2019-07-10 at 16:04.","DSpace SAF Submission Ingestion Package generated from Vireo submission #14248 on 2019-11-26 at 14:03:41","Made available in DSpace on 2019-11-26T20:59:44Z (GMT). No. of bitstreams: 5 TUNCAY-DISSERTATION-2019.pdf: 2434972 bytes, checksum: db6fc3ccb31e3150fdb5f9f5978f9890 (MD5) UIUC Thesis.zip: 8003616 bytes, checksum: 2075ac203dc5affe0148e5ba7ca72885 (MD5) LICENSE.txt: 4209 bytes, checksum: f984b9c329e6358d2015ccfa0d43c18a (MD5) Tuncay Permission letter 2.pdf: 957084 bytes, checksum: a44a5fee7337cd7a607dbda966c913fd (MD5) Tuncay Permission letter.pdf: 19532 bytes, checksum: 5c64e90218dbaf18e11e50dc4ab1110e (MD5) Previous issue date: 2019-07-10","Embargo set by: Seth Robbins for item 113076 Lift date: 2021-11-26T20:59:54Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Open Restriction set for Item 113076 on 2020-10-30T15:38:01Z with date null by astein@illinois.edu.","Open Restriction set for Item 113076 on 2020-10-30T15:38:03Z with date null by astein@illinois.edu.","Limited Restriction set for Item 113076 on 2020-10-30T15:43:36Z with date 2021-08-01 by astein@illinois.edu.","Limited Restriction set for Item 113076 on 2020-10-30T15:43:39Z with date 2021-08-01 by astein@illinois.edu.","Open Restriction set for Item 113076 on 2020-12-17T14:13:57Z with date null by madinag@illinois.edu.","Open Restriction set for Item 113076 on 2020-12-17T14:14:03Z with date null by madinag@illinois.edu.","Open"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/105929"],"dc:language":["en"],"dc:rights":["Copyright 2019 Güliz Seray Tuncay"],"dc:subject":["mobile security, cross-origin interactions, access control, Android"],"dc:title":["Practical least privilege for cross-origin interactions on mobile operating systems"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:45Z"}