A Markov adversary model to detect vulnerable iOS devices and vulnerabilities in iOS apps

被引:26
作者
D'Orazio, Christian J. [1 ]
Lu, Rongxing [2 ]
Choo, Kim-Kwang Raymond [1 ,3 ,4 ]
Vasilakos, Athanasios V. [5 ]
机构
[1] Univ South Australia, Sch Informat Technol & Math Sci, Adelaide, SA, Australia
[2] Univ New Brunswick, Fac Comp Sci, Fredericton, NB E3B 5A3, Canada
[3] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA
[4] China Univ Geosci, Sch Comp Sci, Wuhan, Peoples R China
[5] Lulea Univ Technol, Dept Comp Sci Elect & Space Engn, Lulea, Sweden
关键词
Mobile device vulnerability; Mobile security and privacy; Mobile threats; Vulnerability discovery; Vulnerability exploitation; iOS device vulnerability; SECURITY;
D O I
10.1016/j.amc.2016.08.051
中图分类号
O29 [应用数学];
学科分类号
070104 ;
摘要
With the increased convergence of technologies whereby a user can access, store and transmit data across different devices in real-time, risks will arise from factors such as lack of appropriate security measures in place and users not having requisite levels of security awareness and not fully understanding how security measures can be used to their advantage. In this paper, we adapt our previously published adversary model for digital rights management (DRM) apps and demonstrate how it can be used to detect vulnerable iOS devices and to analyse (non-DRM) apps for vulnerabilities that can potentially be exploited. Using our adversary model, we investigate several (jailbroken and non-jailbroken) iOS devices, Australian Government Medicare Expert Plus (MEP) app, Commonwealth Bank of Australia app, Western Union app, PayPal app, PocketCloud Remote Desktop app and Simple Transfer Pro app, and reveal previously unknown vulnerabilities. We then demonstrate how the identified vulnerabilities can be exploited to expose the user's sensitive data and personally identifiable information stored on or transmitted from the device. We conclude with several recommendations to enhance the security and privacy of user data stored on or transmitted from these devices. (C) 2016 Elsevier Inc. All rights reserved.
引用
收藏
页码:523 / 544
页数:22
相关论文
共 66 条
[1]  
[Anonymous], 2012, P 2012 ACM C COMP CO
[2]  
[Anonymous], 2013, P 39 EUR C EXH OPT C
[3]  
[Anonymous], MOB APP REP REP
[4]  
[Anonymous], 2015, IOS SEC
[5]  
[Anonymous], TRANSPORT LAYER SECU
[6]  
[Anonymous], 2009, ADV INFORM SECURITY
[7]  
Apple, 2015, DEL APP HAS CONF PRO
[8]  
Apple, 2007, CCCRYPT MAC DEV LIB
[9]  
Apple, 2007, CCHMAC MAC DEV LIB R
[10]  
Apple, 2006, APPL COMMONCRYPTOR O