电信科学 ›› 2016, Vol. 32 ›› Issue (10): 42-49.doi: 10.11959/j.issn.1000-0801.2016254

• 专题:基于Android系统的终端安全 • 上一篇    下一篇

一种基于Android系统漏洞的通用攻击模型

邓习海,冯维淼,马璐萍,李莹   

  1. 中国科学院信息工程研究所,北京100093
  • 出版日期:2016-10-15 发布日期:2017-04-27
  • 基金资助:
    中国科学院先导专项基金资助项目

A general attack model based on Android system vulnerability

Xihai DENG,Weimiao FENG,Luping MA,Ying LI   

  1. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
  • Online:2016-10-15 Published:2017-04-27
  • Supported by:
    Strategy Pilot Project of Chinese Academy of Sciences

摘要:

Android系统中的各类漏洞给Android平台的安全性带来了巨大威胁。漏洞利用技术、移动操作系统安全、Android生态系统安全逐渐成为研究热点。从漏洞利用的角度出发,分析典型系统漏洞的利用过程,提出了一种Android系统漏洞利用的通用模型,并构建了一个漏洞利用有效性评估框架。验证结果表明,该模型能够较好地表述黑色产业链中利用漏洞实施攻击的过程。同时,有效性评估框架可以评估特定漏洞对Android生态系统安全性的影响。

关键词: Android操作系统, 系统漏洞, 漏洞利用, 有效性评估

Abstract:

Various kinds of vulnerabilities in Android system bring great threats to the platform. The vulnerability exploitation technology,the security of mobile operating systems and the security of Android ecosystem have become a research focus in both industry and academia. The exploitation of several typical system vulnerabilities was analyzed, a general model of Android system vulnerability exploitation was proposed, and a novel evaluation framework for the effectiveness of vulnerability exploitation was presented. The experiment result shows that the general model is able to accurately describe the process of hacker attacks using Android system vulnerabilities. Furthermore, the evaluation framework can assess the influence of system vulnerabilities on the security of Android ecosystem.

Key words: Android operating system, system vulnerability, vulnerability exploitation, effectiveness evaluation

No Suggested Reading articles found!