Title
BorderPatrol: Securing BYOD using Fine-Grained Contextual Information
Abstract
Companies adopt Bring Your Own Device (BYOD) policies extensively, for both convenience and cost management. The compelling way of putting private and business related applications (apps) on the same device leads to the widespread usage of employee owned devices to access sensitive company data and services. Such practices create a security risk as a legitimate app may send business-sensitive data to third party servers through detrimental app functions or packaged libraries. In this paper, we propose BorderPatrol, a system for extracting contextual data that businesses can leverage to enforce access control in BYOD-enabled corporate networks through fine-grained policies. BorderPatrol extracts contextual information, which is the stack trace of the app function that generated the network traffic, on provisioned user devices and transfers this data in IP headers to enforce desired policies at network routers. BorderPatrol provides a way to selectively prevent undesired functionalities, such as analytics activities or advertisements, and help enforce information dissemination policies of the company while leaving other functions of the app intact. Using 2,000 apps, we demonstrate that BorderPatrol is effective in preventing packets which originate from previously identified analytics and advertisement libraries from leaving the network premises. In addition, we show BorderPatrol's capability in selectively preventing undesirable app functions using case studies.
Year
DOI
Venue
2019
10.1109/DSN.2019.00054
2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
Keywords
DocType
ISSN
mobile platforms,bring your own device,network security,android security,enterprise security,Android
Conference
1530-0889
ISBN
Citations 
PageRank 
978-1-7281-0058-6
1
0.35
References 
Authors
13
4
Name
Order
Citations
PageRank
Onur Zungur110.69
Guillermo Suarez-Tangil2452.84
Gianluca Stringhini370161.87
Manuel Egele41613102.07