tailieunhanh - Systematic Detection of Capability Leaks in Stock Android Smartphones

The purpose of this paper is to highlight some of the most significant US sanctions risks faced by persons that operate in the securities and investment marketplace, in order to encourage firms to maintain comprehensive, risk-based compliance controls that will strengthen their ability to comply with US sanctions regulations. Design/methodology/approach – The paper begins with a brief overview of the sanctions programs administered by the US Treasury Department’s Office of Foreign Assets Control (OFAC), followed by examples of potential sanctions violations that emphasize the risks and challenges faced by the securities and investment sector with respect to sanctions. Finally, the paper describes how firms can develop measures intended. | Systematic Detection of Capability Leaks in Stock Android Smartphones Michael Grace Yajin Zhou Zhi Wang Xuxian Jiang North Carolina State University 890 Oval Drive Raleigh NC 27695 mcgrace yajin zhou zhi_wang @ jiang@ Abstract Recent years have witnessed a meteoric increase in the adoption of smartphones. To manage information and features on such phones Android provides a permission-based security model that requires each application to explicitly request permissions before it can be installed to run. In this paper we analyze eight popular Android smartphones and discover that the stock phone images do not properly enforce the permission model. Several privileged permissions are unsafely exposed to other applications which do not need to request them for the actual use. To identify these leaked permissions or capabilities we have developed a tool called Woodpecker. Our results with eight phone images show that among 13 privileged permissions examined so far 11 were leaked with individual phones leaking up to eight permissions. By exploiting them an untrusted application can manage to wipe out the user data send out SMS messages or record user conversation on the affected phones - all without asking for any permission. 1 Introduction Recent years have witnessed a meteoric increase in the adoption of smartphones. According to data from IDC 24 smartphone manufacturers shipped million units in the fourth quarter of 2010 compared to million units of PCs shipped worldwide. For the first time in history smartphones are outselling personal computers. Their popularity can be partially attributed to the incredible functionality and convenience smartphones offered to end users. In fact existing mobile phones are not simply devices for making phone calls and receiving SMS messages but powerful communication and entertainment platforms for web surfing social networking GPS navigation and online banking. The popularity of smartphones is also .

TỪ KHÓA LIÊN QUAN
crossorigin="anonymous">
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.