Survey of Android OS security

被引:0
|
作者
National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing [1 ]
101408, China
机构
[1] National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing
来源
Jisuanji Yanjiu yu Fazhan | / 7卷 / 1385-1396期
关键词
Android; Authentication mechanism; Malicious application; Security; Survey; Vulnerability;
D O I
10.7544/issn1000-1239.2014.20140098
中图分类号
学科分类号
摘要
Android is an operating system applied to smart mobile device which claims a huge market share. The study of its security has attracted wide attention. In this paper, we introduce Android's system architecture and security mechanism, discuss its security performance and the current research situation from two perspectives: system security and application security. Android's system security includes kernel security, architecture security and user authentications mechanism security. The threats on kernel security and architecture security are mainly from vulnerability. The study of kernel security is focused on how to introduce SELinux into the kernel to improve the security performance, and the study of architecture security is focused on how to improve the performance of permission mechanism and how to implement APIs (application programming interface) securely and to guide developers to use APIs normatively. User authentications mechanism is closely related to user's privacy security and can be implemented flexibly, so that the study on its security has received wide attention. Android's application security includes two technologies which are malicious application detection and vulnerability mining. We discuss on malicious application detection from the counterfeit technology of malicious applications and detection technology of malicious application at installation or running process, and discuss on vulnerability mining from component exposed vulnerabilities and security APIs related vulnerabilities. Finally, we summarize current research situation of Android's security study and propose the issues which are worth further study.
引用
收藏
页码:1385 / 1396
页数:11
相关论文
共 49 条
  • [1] Worldwide smartphone sales in Q3 2013, (2012)
  • [2] Number of available Android applications
  • [3] Keep your phone safe-How to protect yourself from wireless threat
  • [4] BSides Las Vegas: Your droid has no clothes
  • [5] Vulnerability summary for CVE-2012-0056
  • [6] Nakamura Y., Sameshima Y., SELinux for consumer electronics devices, pp. 125-133, (2008)
  • [7] Bugiel S., Davi L., Dmitrienko A., Et al., Practical and lightweight domain isolation on android, pp. 51-62, (2011)
  • [8] Smalley S., Craig R., Security enhanced (SE) Android: bringing flexible MAC to Android, (2013)
  • [9] Kim S.H., Han D., Lee D.H., Predictability of Android OpenSSL's pseudo random number generator, pp. 659-668, (2013)
  • [10] Peng H., Gates C., Sarma B., Et al., Using probabilistic generative models for ranking risks of android apps, pp. 241-252, (2012)