首页> 外文会议>International Conference on Cloud Computing and Security >System Log-Based Android Root State Detection
【24h】

System Log-Based Android Root State Detection

机译:基于系统日志的Android根状态检测

获取原文

摘要

Android rooting enables device owners to freely customize their own devices. However, rooting system weakens the security of Android devices and opens the backdoor for malware to obtain privileged access easily. For this reason, some developers have introduced detection mechanisms for sensitive or high-value mobile apps to mitigate the potential security risks. Nevertheless, the existing root prevention and detection methods generally lack universality. In this paper, we studied the existing Android root detection methods and found the both parties have ignored the traces of the relevant behavior in the log. Thus, we proposed the system log based root state detection method. In the method, we directly use the existing log information to find clues to verify the system root state on one hand, on the other hand, to use the triggering features of some special operations to update and enrich the log information. The results show that, even be deliberately erased, some log information is still remained which can be used to verify whether system was rooted or not.
机译:Android生根技术使设备所有者可以自由自定义其自己的设备。但是,生根系统会削弱Android设备的安全性,并为恶意软件打开后门,从而使恶意软件轻松获得特权访问。因此,一些开发人员已针对敏感或高价值的移动应用程序引入了检测机制,以减轻潜在的安全风险。然而,现有的根预防和检测方法通常缺乏通用性。在本文中,我们研究了现有的Android根目录检测方法,发现双方都忽略了日志中相关行为的痕迹。因此,我们提出了基于系统日志的根状态检测方法。在该方法中,我们一方面直接使用现有的日志信息寻找线索来验证系统的根状态,另一方面利用某些特殊操作的触发功能来更新和丰富日志信息。结果表明,即使有意删除,仍会保留一些日志信息,这些信息可用于验证系统是否植根。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号