Publication | Closed Access
Aurasium: practical policy enforcement for Android applications
374
Citations
25
References
2012
Year
Unknown Venue
Android’s growing popularity has made it a prime target for mobile malware, yet most security research requires OS modifications that impair usability and hinder adoption. Aurasium is designed to provide robust security and privacy controls without modifying the Android OS. It automatically repackages apps to embed user‑level sandboxing and policy enforcement code that monitors for sensitive data leaks, covert SMS, malicious IP access, and prevents privilege‑escalation attacks. Experiments demonstrate near‑100 % success applying Aurasium to a large set of benign and malicious apps with negligible performance and storage overhead, and it has been tested on three Android versions and is freely available.
The increasing popularity of Google's mobile platform Android makes it the prime target of the latest surge in mobile malware. Most research on enhancing the platform's security and privacy controls requires extensive modification to the operating system, which has significant usability issues and hinders efforts for widespread adoption. We develop a novel solution called Aurasium that bypasses the need to modify the Android OS while providing much of the security and privacy that users desire. We automatically repackage arbitrary applications to attach user-level sandboxing and policy enforcement code, which closely watches the application's behavior for security and privacy violations such as attempts to retrieve a user's sensitive information, send SMS covertly to premium numbers, or access malicious IP addresses. Aurasium can also detect and prevent cases of privilege escalation attacks. Experiments show that we can apply this solution to a large sample of benign and malicious applications with a near 100 percent success rate, without significant performance and space overhead. Aurasium has been tested on three versions of the Android OS, and is freely available.
| Year | Citations | |
|---|---|---|
Page 1
Page 1