The Demon is in the Configuration

Abeer AlJarrah, Mohamed Elemam Shehab · 2017

HTML-5 hybrid apps have the potential to dominate the mobile and IoTs market as hybrid platforms are providing a promising development choice. This approach "wraps" standard web code (HTML, Javascript, and CSS) into a thin native layer, enabling the same code base to run on several platforms. This approach also provides a mechanism to access device native sensors, such as camera and geolocation, through Javascript code. Apache Cordova is an open source library that is a common component in many hybrid platforms, such as PhoneGap and IBM Worklight. Yet, its configuration model suffers several security limitations including a coarse-grained access control model, risky defaults, and for many developers, a non-trivial configuration process. Hybrid app development is an intricate task as is, not to mention configuring these apps securely. Given the increased popularity of the approach itself and the proven tendency of developers to use platform-provided default settings, this paper presents a novel approach to automatically generate configurations that are more aligned to the app requirements, more granular, and more conformant with Least Privilege principle. We argue that having aligned configurations forms the first line of defense against attacks similar to injection attacks. Such attacks could have been voided if the app configurations were more granular and tailored. Our approach generates initial configuration settings based on modeling app behavior. The model generates twofold policies, one centered around APIs access and another around controlling app states transition. We have successfully instrumented Cordova library to implement our approach. We have tested the instrumented version, and our experiments demonstrate that the instrumented version is a practical and performant alternative.

Read the paper · More papers on PaperTik