首页> 外文学位 >Rubicon: Un nuevo enfoque para la seguridad en las aplicaciones de smartphones.
【24h】

Rubicon: Un nuevo enfoque para la seguridad en las aplicaciones de smartphones.

机译:Rubicon:智能手机应用程序安全性的新方法。

获取原文
获取原文并翻译 | 示例

摘要

The number of smartphones has grown exponentially in recent years. These devices, which have a big mobility and dedicated hardware (i.e., GPS or gyroscope), are guided by complex operating systems. In addition, the proliferation of application stores has generated a new easy way to install tools and games directly on device.;Unfortunately, the security management of these devices is far from optimal. The proliferation of malicious applications (malware) in these platforms, added to the fact that the access of these applications to sensible data is made behind the backs of users, has created a new scene. In this new scenario, these devices store a huge amount of private and sensitive data (e.g., short messages or e-mails), and their security is not as mature as in other environments, for example in personal computers.;The scientific community has accepted the challenge and is looking for solutions. To this end, they have tried to migrate models from desktop environment to these devices with mixed fortunes. Some researchers have developed representations of applications and, after that, they apply machine learning techniques with different results.;Against this background, the main goal of this research is to mitigate the threats to which these devices are exposed to, through the surveillance of installed applications, without any user interaction. Therefore, we formulate the following hypothesis: "It is possible, using supervised algorithms of artificial intelligence and data mining, to deploy an intelligent, automatic and effective security layer for smartphones to release the user from the responsibility for managing the safety.".;In order to validate this hypothesis, first we made an exhaustive evaluation of the existing solutions. Then, we developed a new threat modelling in these devices. To validate this model, we have developed a new bank of attacks, which defines the assets, threats, attacks and vulnerabilities that occurs in these devices.;After evaluating the results, we concluded that malicious software is the biggest threat facing these devices. Then, we designed and developed a solution which enhanced this situation. We use Android platform to validate this solution and evaluate this using metrics that are applied in machine learning area and contrast them based on previously selected criteria. Through this investigation we want to advance in the state of the art of malware detection in smartphones, progressing in creation a safe environment for the use of such systems.
机译:近年来,智能手机的数量呈指数增长。这些设备具有很大的移动性和专用硬件(即GPS或陀螺仪),并由复杂的操作系统引导。此外,应用程序商店的激增为直接在设备上安装工具和游戏提供了一种简便的新方法。不幸的是,这些设备的安全性管理远未达到最佳状态。这些平台中恶意应用程序(恶意软件)的激增,加之事实是,这些应用程序对敏感数据的访问是在用户的背后进行的,这创造了一个新的场景。在这种新情况下,这些设备存储了大量的私有和敏感数据(例如,短消息或电子邮件),并且其安全性不如在其他环境中(例如在个人计算机中)成熟。接受了挑战,正在寻找解决方案。为此,他们尝试将模型从台式机环境迁移到这些设备的时光倒流。一些研究人员开发了应用程序的表示形式,然后,他们应用了机器学习技术并获得了不同的结果。在这种背景下,本研究的主要目标是通过监视安装的设备来减轻这些设备所面临的威胁。应用程序,无需任何用户交互。因此,我们提出以下假设:“有可能使用受监督的人工智能和数据挖掘算法,为智能手机部署智能,自动和有效的安全层,以使用户摆脱管理安全的责任。”;为了验证该假设,首先我们对现有解决方案进行了详尽的评估。然后,我们在这些设备中开发了新的威胁模型。为了验证该模型,我们开发了一种新的攻击库,其中定义了这些设备中发生的资产,威胁,攻击和漏洞。在评估结果之后,我们得出结论,恶意软件是这些设备面临的最大威胁。然后,我们设计并开发了一种解决方案,可以改善这种情况。我们使用Android平台来验证该解决方案,并使用机器学习领域中应用的指标对其进行评估,并根据先前选择的标准对它们进行对比。通过这项调查,我们希望提高智能手机中恶意软件检测的技术水平,并在创建使用此类系统的安全环境方面取得进展。

著录项

  • 作者

    Sanz Urquijo, Borja.;

  • 作者单位

    Universidad de Deusto (Spain).;

  • 授予单位 Universidad de Deusto (Spain).;
  • 学科 Engineering Computer.;Artificial Intelligence.
  • 学位 Ph.D.
  • 年度 2012
  • 页码 230 p.
  • 总页数 230
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号