首页> 外文会议>Conference on Information Assurance and Cyber Security >Signature-based detection of privilege-escalation attacks on Android
【24h】

Signature-based detection of privilege-escalation attacks on Android

机译:基于签名的Android特权升级攻击检测

获取原文

摘要

Android has become a major player in smartphone software arena, thanks to the massively positive reception of Google Play by the developers and users alike. In general, Android applications follow a set of permissions, which are used for access control. However, through the privilege-escalation vulnerability, a malicious application can escalate itself and access an un-permitted resource. Consequently, serious security and safety exploits such as privacy violation, reverse-shell access to the device, and drive-by downloads may occur. We propose a flexible and efficient defense mechanism against such exploits. Our solution - SAndroid, is an extensible and a lightweight application. It provides enhanced safety and security against privilege escalation attacks through rapid detection. SAndroid is based on active monitoring and detection of malicious applications through tracking of system logs and malicious process signatures. The assurance of safety provided by SAndroid is confirmed through design, testing, and verification. SAndroid follows modular approach permitting high flexibility and efficiency. Through real experiments, we confirmed that SAndroid is an efficient and low cost solution having negligible false-positives. This paper describes the architecture and design of the SAndroid framework and provides details of our experiments.
机译:得益于开发人员和用户的广泛好评,Android已成为智能手机软件领域的主要参与者。通常,Android应用程序遵循一组权限,这些权限用于访问控制。但是,通过特权升级漏洞,恶意应用程序可以升级自身并访问未经许可的资源。因此,可能会发生严重的安全和漏洞利用,例如侵犯隐私,对设备的反向外壳访问以及偷渡式下载。我们提出了一种灵活,有效的防御机制来抵御此类攻击。我们的解决方案-SAndroid是一个可扩展的轻量级应用程序。它可以通过快速检测来增强针对特权升级攻击的安全性。 SAndroid通过跟踪系统日志和恶意进程签名,基于对恶意应用程序的主动监视和检测。通过设计,测试和验证,可以确定SAndroid提供的安全性保证。 SAndroid遵循模块化方法,具有很高的灵活性和效率。通过实际实验,我们确认SAndroid是一种有效且低成本的解决方案,其误报率可以忽略不计。本文介绍了SAndroid框架的体系结构和设计,并提供了我们实验的详细信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号