DocumentCode :
3739058
Title :
Signature-based detection of privilege-escalation attacks on Android
Author :
Rafay Hassan Niazi;Jawwad Ahmed Shamsi;Tahir Waseem;Muhammad Mubashir Khan
Author_Institution :
Computer Information Systems, NED University of Engineering & Technology, Karachi, Pakistan
fYear :
2015
Firstpage :
44
Lastpage :
49
Abstract :
Android has become a major player in smartphone software arena, thanks to the massively positive reception of Google Play by the developers and users alike. In general, Android applications follow a set of permissions, which are used for access control. However, through the privilege-escalation vulnerability, a malicious application can escalate itself and access an un-permitted resource. Consequently, serious security and safety exploits such as privacy violation, reverse-shell access to the device, and drive-by downloads may occur. We propose a flexible and efficient defense mechanism against such exploits. Our solution - SAndroid, is an extensible and a lightweight application. It provides enhanced safety and security against privilege escalation attacks through rapid detection. SAndroid is based on active monitoring and detection of malicious applications through tracking of system logs and malicious process signatures. The assurance of safety provided by SAndroid is confirmed through design, testing, and verification. SAndroid follows modular approach permitting high flexibility and efficiency. Through real experiments, we confirmed that SAndroid is an efficient and low cost solution having negligible false-positives. This paper describes the architecture and design of the SAndroid framework and provides details of our experiments.
Keywords :
"Androids","Humanoid robots","Security","Monitoring","Browsers","Internet","Safety"
Publisher :
ieee
Conference_Titel :
Information Assurance and Cyber Security (CIACS), 2015 Conference on
Type :
conf
DOI :
10.1109/CIACS.2015.7395565
Filename :
7395565
Link To Document :
بازگشت