FP7Individual fellowship2012–2014

ACTIVMOBSEC · Active Behaviour Demands Active Security: New Approaches to Mobile Device Security

FP7 — People (Marie Curie Actions)

Duration
2012-09-28 → 2014-09-27
EU contribution
€200,372
Participants
1
Scheme
MC-IIF

Lines connect the coordinator with its partners.

Results in brief

Active Behaviour Demands Active Security: New Approaches to Mobile Device Security

The project “Active Behaviour Demands Active Security: New Approaches to Mobile Device Security (ACTIVMOBSEC)” (PIIF GA 2011 301536) ran from 28/09/2012 to 27/09/2014. This project investigated efficient modelling techniques to establish behaviour profiles on smart phone mobile devices. We hypothesized that behaviour remains stable under day to day use while anomalies will be observed under attack. Our results confirmed this hypothesis. The project had four objectives: • O1. Determine the most suitable sources for data modelling. • O2. Develop scalable algorithms for behaviour modelling. • O3. Determine suitable system status views for the user to make better informed decisions. • O4. To provide means for analyzing unknown behaviour. through the use of clustering of collected legitimate and malicious behaviour. For O1 we developed a sensor collection application, and ran several small data collection studies to find viable sensor outputs from mobile devices. From this work, we collected data from sensors that record activities *on* the phone (application, phone, CPU, and battery use) as well as activities *around* the phone (light, noise, rotation, magnetic field, cell towers, and WiFi access points). For O2 we investigated the use of existing modelling techniques, e.g., based on decision trees, and defined our own spatial and temporal models. We adapted them to measure both discrete and continuous data from sensors from which we (i) built dictionaries of frequent sensor events (e.g., frequent app use at particular locations), and (ii) measured “comfort” for each individual sensor. For O3 we created some innovative ways of not overburdening participants when determining the “ground truth” of the data. We also built a data collection app with a user friendly interface for collecting sensor data, and used this with our data collection and analysis. Objective O4 was carried out during months 16 to 24. For this objective we defined threat models in order to measure the security of implicit authentication, and simultaneously evaluated trade-offs for battery consumption with different techniques for optimizing sensor use. Our results demonstrate the viability of an implicit authentication solution for mobile devices, and we made key contributions in terms of sensor behaviour models and efficient sensor data collection, and were able to scientifically demonstrate the security and usability of our solutions. As noted above the work resulted in several high-quality publications and received recognition in several press articles (Evening Times and Metro in Feb 2012 at the start of our project, and later with some initial results in BBC News in Feb 2014, and New Scientist and Daily Mail in November 2014). http://ittgroup.org/all-projects

Data: CORDIS, © European Union

Project objective

As mobile devices are increasingly used in day-to-day tasks involving sensitive information, authentication and money, they are becoming attractive targets for attackers. Recent attacks against mobile devices have succeeded in leaking the sensitive information stored on the device and have provided attackers financial gain through the unauthorized use of phone and messaging services.While the current state-of-the-art is designed with security in mind and provides a level of protection they are static and have a major assumption: every user will download applications from the ‘official app store’ in which, submitted applications are statically checked and validated prior to being admitted. The app store validation is mainly based on permission checks and code verification prior to installation. However, once the application passes and makes its way to the user’s mobile device, no further security checks occur. This leaves the users open for sophisticated attacks involving various data leak cases or the interaction of existing applications on the device.Therefore, ACTIVMOBSEC proposes an active approach based on user and application behaviour modelling, similar but not identical to anomaly detection, for detecting the behaviour changes on the device. The main challenge is to differentiate between legitimate changes (i.e., software updates) and the malicious acts such as device theft, malware infection or data leaks. To this end, ACTIMOBSEC aims to improve the user awareness and provide clear and concise information on the device state. Furthermore, a user centric validation technique will be investigated to provide a way for only the legitimate user to train his/her device while the malicious use and users will cause the device to operate in a defensive state, preventing access to sensitive data and functions.

Original text from CORDIS.

Participants

Links

Data: CORDIS, © European Union