An empirical performance and security evaluation of android container solutions

Tianhui Meng, Zhihao Shang, K. Wolter
{"title":"An empirical performance and security evaluation of android container solutions","authors":"Tianhui Meng, Zhihao Shang, K. Wolter","doi":"10.1109/CyberSecPODS.2017.8074850","DOIUrl":null,"url":null,"abstract":"Bring Your Own Device (BYOD) security is a concern for many companies' IT departments. Many corporations implement a “secure container” solution that provides full separation of work and personal data on mobile devices to mitigate the dangers brought by BYOD. In this paper, we perform an empirical comparison between two popular secure containers for Android: Samsung Knox and IBM MaaS360. We first conduct benchmark tests to compare these two containers. Then in order to quantitatively assess the security property of these containers, we propose a measurement method based on a simulating attack. Our experimental results show that performance of compute-intensive applications in the Knox container will be affected drastically compared with when they are running on the device (outside the container), while for memory-intensive applications, performance will not deteriorate much in Knox and MaaS360 containers. We also found that with an overhead of 3.3 ms (0.58%) in mean response time, Knox container can extend the mean time to security failure (MTTSF) by 109.6 min (878%). Within the MaaS360 container, the MTTSF is prolonged by 10.2 min (81.4%) but the response time is 3.3 ms (0.58%) longer per job than without containers.","PeriodicalId":203945,"journal":{"name":"2017 International Conference on Cyber Security And Protection Of Digital Services (Cyber Security)","volume":"61 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 International Conference on Cyber Security And Protection Of Digital Services (Cyber Security)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CyberSecPODS.2017.8074850","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Bring Your Own Device (BYOD) security is a concern for many companies' IT departments. Many corporations implement a “secure container” solution that provides full separation of work and personal data on mobile devices to mitigate the dangers brought by BYOD. In this paper, we perform an empirical comparison between two popular secure containers for Android: Samsung Knox and IBM MaaS360. We first conduct benchmark tests to compare these two containers. Then in order to quantitatively assess the security property of these containers, we propose a measurement method based on a simulating attack. Our experimental results show that performance of compute-intensive applications in the Knox container will be affected drastically compared with when they are running on the device (outside the container), while for memory-intensive applications, performance will not deteriorate much in Knox and MaaS360 containers. We also found that with an overhead of 3.3 ms (0.58%) in mean response time, Knox container can extend the mean time to security failure (MTTSF) by 109.6 min (878%). Within the MaaS360 container, the MTTSF is prolonged by 10.2 min (81.4%) but the response time is 3.3 ms (0.58%) longer per job than without containers.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
android容器解决方案的性能和安全性实证评估
自带设备(BYOD)安全是许多公司IT部门关心的问题。许多公司实施“安全容器”解决方案,在移动设备上提供完全分离的工作和个人数据,以减轻BYOD带来的危险。在本文中,我们对两种流行的Android安全容器:Samsung Knox和IBM MaaS360进行了实证比较。我们首先执行基准测试来比较这两个容器。然后,为了定量评估这些容器的安全性能,我们提出了一种基于模拟攻击的测量方法。我们的实验结果表明,与在设备(容器外)上运行相比,计算密集型应用程序在Knox容器中的性能将受到极大影响,而对于内存密集型应用程序,在Knox和MaaS360容器中性能不会下降太多。我们还发现,在平均响应时间开销为3.3 ms(0.58%)的情况下,Knox容器可以将安全故障(MTTSF)的平均时间延长109.6 min(878%)。在MaaS360容器中,MTTSF延长了10.2分钟(81.4%),但每个作业的响应时间比没有容器时长3.3毫秒(0.58%)。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Security operations centre: Situation awareness, threat intelligence and cybercrime ROPK++: An enhanced ROP attack detection framework for Linux operating system When eHealth meets the internet of things: Pervasive security and privacy challenges Foiling cyber attacks PrincessLocker analysis
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1