Profiling Vulnerabilities Threatening Dual Persona in Android Framework

K. Siddiquie, Narmeen Shafqat, A. Masood, Haider Abbas, W. Shahid
{"title":"Profiling Vulnerabilities Threatening Dual Persona in Android Framework","authors":"K. Siddiquie, Narmeen Shafqat, A. Masood, Haider Abbas, W. Shahid","doi":"10.1109/AECT47998.2020.9194151","DOIUrl":null,"url":null,"abstract":"Enterprises round the globe have been searching for a way to securely empower AndroidTM devices for work but have spurned away from the Android platform due to ongoing fragmentation and security concerns. Discrepant vulnerabilities have been reported in Android smartphones since Android Lollipop release. Smartphones can be easily hacked by installing a malicious application, visiting an infectious browser, receiving a crafted MMS, interplaying with plug-ins, certificate forging, checksum collisions, inter-process communication (IPC) abuse and much more. To highlight this issue a manual analysis of Android vulnerabilities is performed, by using data available in National Vulnerability Database NVD and Android Vulnerability website. This paper includes the vulnerabilities that risked the dual persona support in Android 5 and above, till Dec 2017. In our security threat analysis, we have identified a comprehensive list of Android vulnerabilities, vulnerable Android versions, manufacturers, and information regarding complete and partial patches released. So far, there is no published research work that systematically presents all the vulnerabilities and vulnerability assessment for dual persona feature of Android’s smartphone. The data provided in this paper will open ways to future research and present a better Android security model for dual persona.","PeriodicalId":331415,"journal":{"name":"2019 International Conference on Advances in the Emerging Computing Technologies (AECT)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2020-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 International Conference on Advances in the Emerging Computing Technologies (AECT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/AECT47998.2020.9194151","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Enterprises round the globe have been searching for a way to securely empower AndroidTM devices for work but have spurned away from the Android platform due to ongoing fragmentation and security concerns. Discrepant vulnerabilities have been reported in Android smartphones since Android Lollipop release. Smartphones can be easily hacked by installing a malicious application, visiting an infectious browser, receiving a crafted MMS, interplaying with plug-ins, certificate forging, checksum collisions, inter-process communication (IPC) abuse and much more. To highlight this issue a manual analysis of Android vulnerabilities is performed, by using data available in National Vulnerability Database NVD and Android Vulnerability website. This paper includes the vulnerabilities that risked the dual persona support in Android 5 and above, till Dec 2017. In our security threat analysis, we have identified a comprehensive list of Android vulnerabilities, vulnerable Android versions, manufacturers, and information regarding complete and partial patches released. So far, there is no published research work that systematically presents all the vulnerabilities and vulnerability assessment for dual persona feature of Android’s smartphone. The data provided in this paper will open ways to future research and present a better Android security model for dual persona.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
分析Android框架中威胁双重角色的漏洞
全球各地的企业一直在寻找一种方法来安全地授权Android tm设备进行工作,但由于持续的碎片化和安全问题,他们已经放弃了Android平台。自Android Lollipop发布以来,Android智能手机中出现了不同的漏洞。通过安装恶意应用程序、访问具有传染性的浏览器、接收精心制作的彩信、与插件交互、伪造证书、校验和冲突、滥用进程间通信(IPC)等等,智能手机很容易被黑客入侵。为了突出这一问题,通过使用国家漏洞数据库NVD和Android漏洞网站中的数据,对Android漏洞进行了手动分析。本文包含了2017年12月之前Android 5及以上版本存在双重角色支持风险的漏洞。在我们的安全威胁分析中,我们已经确定了一个完整的Android漏洞列表,易受攻击的Android版本,制造商以及有关发布的完整和部分补丁的信息。到目前为止,还没有发表的研究工作系统地展示了Android智能手机双重人格特性的所有漏洞和漏洞评估。本文提供的数据将为未来的研究开辟道路,并为双重角色提供更好的Android安全模型。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Permissioned Blockchain-Based Security for SDN in IoT Cloud Networks Educational Business Intelligence Framework Visualizing Significant Features using Metaheuristic Algorithm and Feature Selection A Formal Approach To Validate Block-Chains Software Cost Estimation – A Comparative Study of COCOMO-II and Bailey-Basili Models IoT for Smart Parking
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1