首页> 外文学位 >Vulnerability Detection and Mitigation in Commodity Android Devices.
【24h】

Vulnerability Detection and Mitigation in Commodity Android Devices.

机译:商品Android设备中的漏洞检测和缓解。

获取原文
获取原文并翻译 | 示例

摘要

The smartphone market has grown explosively in recent years, as more and more consumers are attracted to the sensor-studded multipurpose devices. However, with the popularity of Android platform, a large number of vulnerabilities have been observed and exploited in the wild.;In this dissertation, we aim to detect and quantify the presence of vulnerabilities in commodity Android devices, and propose corresponding mitigation solutions. In particular, we focus on two kinds of vulnerabilities, i.e., app-level vulnerabilities in pre-loaded apps and kernel-level vulnerabilities in device firmware images. To these ends, we first propose a system named SEFA to detect app-level vulnerabilities and evaluate their impact. Using SEFA, we quantitatively analyze ten representative stock Android images from five popular smartphone vendors (with two models from each vendor). Our evaluation results are worrisome: all examined devices are vulnerable. Our results also show that vendor customizations are significant on stock Android devices and on the whole responsible for the bulk of the security problems we detected in each device. To make matter worse, the slow update cycle makes the threats more serious, since it provides the attackers with more opportunities to launch the attack. (Abstract shortened by ProQuest.).
机译:近年来,随着越来越多的消费者被带有传感器的多功能设备所吸引,智能手机市场爆发式增长。然而,随着Android平台的普及,已经在野外发现并利用了大量的漏洞。本文旨在检测和量化商品化Android设备中漏洞的存在,并提出相应的缓解措施。特别是,我们重点关注两种漏洞,即预加载应用程序中的应用程序级漏洞和设备固件映像中的内核级漏洞。为此,我们首先提出一个名为SEFA的系统,以检测应用程序级漏洞并评估其影响。使用SEFA,我们定量分析了来自五个受欢迎的智能手机供应商(每个供应商有两个模型)的十张代表性Android图像。我们的评估结果令人担忧:所有检查过的设备都容易受到攻击。我们的结果还表明,供应商的自定义对于库存的Android设备非常重要,并且总体上对我们在每台设备中检测到的大部分安全问题负责。更糟糕的是,缓慢的更新周期使威胁更加严重,因为它为攻击者提供了更多发起攻击的机会。 (摘要由ProQuest缩短。)。

著录项

  • 作者

    Wu, Lei.;

  • 作者单位

    North Carolina State University.;

  • 授予单位 North Carolina State University.;
  • 学科 Computer science.
  • 学位 Ph.D.
  • 年度 2015
  • 页码 99 p.
  • 总页数 99
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号