Cracking the Core: Hardware Vulnerabilities in Android Devices Unveiled

被引:2
作者
Munoz, Antonio [1 ]
机构
[1] Univ Malaga, Network Informat & Comp Secur Lab NICS, Malaga 29071, Spain
关键词
Android hardware vulnerabilities; mobile device security; system-on-chip (SoC) security; trusted execution environment (TEE); hardware vulnerability mitigations; side-channel attacks;
D O I
10.3390/electronics13214269
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As Android devices become more prevalent, their security risks extend beyond software vulnerabilities to include critical hardware weaknesses. This paper provides a comprehensive and systematic review of hardware-related vulnerabilities in Android systems, which can bypass even the most sophisticated software defenses. We compile and analyze an extensive range of reported vulnerabilities, introducing a novel categorization framework to facilitate a deeper understanding of these risks, classified by affected hardware components, vulnerability type, and the potential impact on system security. The paper addresses key areas such as memory management flaws, side-channel attacks, insecure system-on-chip (SoC) resource allocation, and cryptographic vulnerabilities. In addition, it examines feasible countermeasures, including hardware-backed encryption, secure boot mechanisms, and trusted execution environments (TEEs), to mitigate the risks posed by these hardware threats. By contextualizing hardware vulnerabilities within the broader security architecture of Android devices, this review emphasizes the importance of hardware security in ensuring system integrity and resilience. The findings serve as a valuable resource for both researchers and security professionals, offering insights into the development of more robust defenses against the emerging hardware-based threats faced by Android devices.
引用
收藏
页数:26
相关论文
共 67 条
  • [51] Trusted Execution Environment: What It Is, and What It Is Not
    Sabet, Mohamed
    Achemlal, Mohammed
    Bouabdallah, Abdelmadjid
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 57 - 64
  • [52] Boot Attestation: Secure Remote Reporting with Off-The-Shelf IoT Sensors
    Schulz, Steffen
    Schaller, Andre
    Kohnhauser, Florian
    Katzenbeisser, Stefan
    [J]. COMPUTER SECURITY - ESORICS 2017, PT II, 2017, 10493 : 437 - 455
  • [53] Android Source Code Vulnerability Detection: A Systematic Literature Review
    Senanayake, Janaka
    Kalutarage, Harsha
    Al-Kadri, Mhd Omar
    Petrovski, Andrei
    Piras, Luca
    [J]. ACM COMPUTING SURVEYS, 2023, 55 (09)
  • [54] Malicious application detection in android - A systematic literature review
    Sharma, Tejpal
    Rattan, Dhavleesh
    [J]. COMPUTER SCIENCE REVIEW, 2021, 40
  • [55] A Multi-Layered Defence Strategy against DDoS Attacks in SDN/NFV-Based 5G Mobile Networks
    Sheibani, Morteza
    Konur, Savas
    Awan, Irfan
    Qureshi, Amna
    [J]. ELECTRONICS, 2024, 13 (08)
  • [56] Singh R., 2014, Int. J. Eng. Res. Appl, V4, P519
  • [57] Sommerhalder M., 2023, Trends in Data Protection and Encryption Technologies, P83
  • [58] Dynamic Security Analysis on Android: A Systematic Literature Review
    Sutter, Thomas
    Kehrer, Timo
    Rennhard, Marc
    Tellenbach, Bernhard
    Klein, Jacques
    [J]. IEEE ACCESS, 2024, 12 : 57261 - 57287
  • [59] Challenges and Opportunities for Hardware-Assisted Security Improvements in the Field
    Tan, Benjamin
    [J]. PROCEEDINGS OF THE TWENTY THIRD INTERNATIONAL SYMPOSIUM ON QUALITY ELECTRONIC DESIGN (ISQED 2022), 2022, : 90 - 95
  • [60] CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive Networks<bold> </bold>
    Tron, Alvise de Faveri
    Longari, Stefano
    Carminati, Michele
    Polino, Mario
    Zanero, Stefano
    [J]. PROCEEDINGS OF THE 2022 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2022, 2022, : 711 - 723