A taxonomy of privilege escalation attacks in Android applications

被引:16
|
作者
Rangwala, Mohammed [1 ]
Zhang, Ping [2 ]
Zou, Xukai [1 ]
Li, Feng [1 ]
机构
[1] Department of Computer and Information Science, Indiana University Purdue University Indianapolis, Indianapolis, IN 46202, United States
[2] Department of Computer Science and Engineering, Henan Institute of Engineering, Zhengzhou, HN 451191, China
关键词
Android - Android applications - Design and implements - Mobile operating systems - Privilege escalation - Security frameworks - Security mechanism - Smartphone securities;
D O I
10.1504/IJSN.2014.059327
中图分类号
学科分类号
摘要
Google's Android is one of the most popular mobile operating system platforms today, being deployed on a wide range of mobile devices from various manufacturers. It is termed as a privilege-separated operating system which implements some novel security mechanisms. Recent research and security attacks on the platform, however, have shown that the security model of Android is flawed and is vulnerable to transitive usage of privileges among applications. Privilege escalation attacks have been shown to be malicious and with the wide spread and growing use of the system, the platform for these attacks is also growing wider. This provides a motivation to design and implement better security frameworks and mechanisms to mitigate these attacks. This paper discusses; 1) the security features currently provided by the Android platform; 2) a definition, few working examples and classifications of privilege escalation attacks in Android applications; 3) a classification and comparison of different frameworks and security extensions proposed in recent research. Copyright © 2014 Inderscience Enterprises Ltd.
引用
收藏
页码:40 / 55
相关论文
共 50 条
  • [1] Privilege Escalation Attacks on Android
    Davi, Lucas
    Dmitrienko, Alexandra
    Sadeghi, Ahmad-Reza
    Winandy, Marcel
    [J]. INFORMATION SECURITY, 2011, 6531 : 346 - +
  • [2] Role behavior detection method of privilege escalation attacks for android applications
    Li H.
    Shen L.
    Ma C.
    Liu M.
    [J]. International Journal of Performability Engineering, 2019, 15 (06): : 1631 - 1641
  • [3] Privilege Escalation Detecting in Android Applications
    Zhong, Xingqiu
    Zeng, Fanping
    Cheng, Zhichao
    Xie, Niannian
    Qin, Xiaoxia
    Guo, Shuli
    [J]. 2017 3RD INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING AND COMMUNICATIONS (BIGCOM), 2017, : 39 - 44
  • [4] An Adaptive Android Security Extension against Privilege Escalation Attacks
    Xu, Yang
    Ren, Ju
    Zhang, Yaoxue
    Wang, Guojun
    [J]. 2017 15TH IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS AND 2017 16TH IEEE INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING AND COMMUNICATIONS (ISPA/IUCC 2017), 2017, : 752 - 760
  • [5] POSTER: The Quest for Security against Privilege Escalation Attacks on Android
    Bugiel, Sven
    Davi, Lucas
    Dmitrienko, Alexandra
    Fischer, Thomas
    Sadeghi, Ahmad-Reza
    Shastry, Bhargava
    [J]. PROCEEDINGS OF THE 18TH ACM CONFERENCE ON COMPUTER & COMMUNICATIONS SECURITY (CCS 11), 2011, : 741 - 743
  • [6] Curtailing Privilege Escalation Attacks over Asynchronous Channels on Android
    Mollus, Katharina
    Westhoff, Dirk
    Markmann, Tobias
    [J]. 2014 14TH INTERNATIONAL CONFERENCE ON INNOVATIONS FOR COMMUNITY SERVICES (I4CS), 2014, : 87 - 94
  • [7] Signature-based Detection of Privilege-Escalation Attacks on Android
    Niazi, Rafay Hassan
    Waseem, Tahir
    Shamsi, Jawwad Ahmed
    Khan, Muhammad Mubashir
    [J]. 2015 CONFERENCE ON INFORMATION ASSURANCE AND CYBER SECURITY (CIACS), 2015, : 44 - 49
  • [8] A Survey of Privilege Escalation Detection in Android
    Hutchinson, Shinelle
    Varol, Cihan
    [J]. 2018 9TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2018, : 726 - 731
  • [9] Risk measurement method for privilege escalation attacks on android apps based on process algebra
    Shen, Limin
    Li, Hui
    Wang, Hongyi
    Wang, Yihuan
    Feng, Jiayin
    Jian, Yuqing
    [J]. Information (Switzerland), 2020, 11 (06):
  • [10] Research on Non-Authorized Privilege Escalation Detection of Android Applications
    Yang, Yaping
    Cai, Lizhi
    Zhang, Yanguo
    [J]. 2016 17TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNPD), 2016, : 563 - 568