首页> 外文期刊>International Journal on Critical Infrastructure Protection >Security considerations related to the use of mobile devices in the operation of critical infrastructures
【24h】

Security considerations related to the use of mobile devices in the operation of critical infrastructures

机译:与在关键基础架构的操作中使用移动设备有关的安全注意事项

获取原文
获取原文并翻译 | 示例
           

摘要

An increasing number of attacks by mobile malware have begun to target critical infrastructure assets. Since malware attempts to defeat the security mechanisms provided by an operating system, it is of paramount importance to understand the strengths and weaknesses of the security frameworks of mobile device operating systems such as Android. Many recently discovered vulnerabilities suggest that security issues may be hidden in the cross-layer interplay between the Android layers and the underlying Linux kernel. This paper presents an empirical security evaluation of the interactions between Android layers. The experiments indicate that the Android Security Framework does not discriminate between callers of invocations to the Linux kernel, thereby enabling Android applications to directly interact with the kernel. This paper shows how this trait allows malware to adversely affect the security of mobile devices by exploiting previously unknown vulnerabilities unveiled by analyses of the Android interplay. The impact of the resulting attacks on critical infrastructures is discussed. Finally, an enhancement to the Android Security Framework is proposed for detecting and preventing direct kernel invocations by applications, thereby dramatically reducing the impact of malware. (C) 2014 Elsevier B.V. All rights reserved.
机译:越来越多的移动恶意软件攻击已开始针对关键基础设施资产。由于恶意软件试图破坏操作系统提供的安全机制,因此了解诸如Android之类的移动设备操作系统的安全框架的优缺点至关重要。最近发现的许多漏洞表明,安全性问题可能隐藏在Android层和底层Linux内核之间的跨层交互中。本文对Android图层之间的交互进行了经验安全性评估。实验表明,Android安全框架不会区分调用Linux内核的调用者,从而使Android应用程序可以直接与内核进行交互。本文通过利用Android相互作用分析揭示的先前未知的漏洞,展示了此特征如何使恶意软件对移动设备的安全产生不利影响。讨论了由此产生的攻击对关键基础架构的影响。最后,提出了对Android安全框架的增强,以检测和阻止应用程序直接调用内核,从而显着降低了恶意软件的影响。 (C)2014 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号