Publication | Closed Access
All your droid are belong to us: a survey of current android attacks
147
Citations
7
References
2011
Year
Unknown Venue
Mobile SecurityEngineeringInformation SecurityMobile DevicesMobile Device ForensicsCurrent Android AttacksSide-channel AttackTrusted Execution EnvironmentPrivilege SeparationOperating System SecuritySecure By DesignData PrivacyMobile MalwareMobile ComputingComputer ScienceAndroid Security ModelData SecurityCryptographySoftware SecurityCloud Computing
In the past few years, mobile devices (smartphones, PDAs) have seen both their computational power and their data connectivity rise to a level nearly equivalent to that available on small desktop computers, while becoming ubiquitous. On the downside, these mobile devices are now an extremely attractive target for large-scale security attacks. Mobile device middleware is thus experiencing an increased focus on attempts to mitigate potential security compromises. In particular, Android incorporates by design many well-known security features such as privilege separation. The Android security model also creates several new security sensitive concepts such as Android's application permission system and the unmoderated Android market. In this paper we look to Android as a specific instance of mobile computing. We first discuss the Android security model and some potential weaknesses of the model. We then provide a taxonomy of attacks to the platform demonstrated by real attacks that in the end guarantee privileged access to the device. Where possible, we also propose mitigations for the identified vulnerabilities.
| Year | Citations | |
|---|---|---|
Page 1
Page 1