A survey of Android exploits in the wild. Issue 76 (July 2018)
- Record Type:
- Journal Article
- Title:
- A survey of Android exploits in the wild. Issue 76 (July 2018)
- Main Title:
- A survey of Android exploits in the wild
- Authors:
- Meng, Huasong
Thing, Vrizlynn L.L.
Cheng, Yao
Dai, Zhongmin
Zhang, Li - Abstract:
- Abstract: The Android operating system has been dominating the mobile device market in recent years. Although Android has actively strengthened its security mechanisms and fixed a great number of vulnerabilities as its version evolves, new vulnerabilities still keep emerging. Vulnerability exploitation is a common way to achieve privilege escalation on Android systems. In order to provide a holistic and comprehensive understanding of the exploits, we conduct a survey of publicly available 63 exploits for Android devices in this paper. Based on the analysis of the collected real-world exploits, we construct a taxonomy on Android exploitation and present the similarities/differences and strength/weakness of different types of exploits. On the other hand, we conduct an evaluation on a group of selected exploits on our test devices. Based on both the theoretical analysis and the experimental results of the evaluation, we present our insight into the Android exploitation. The growth of exploit categories along the timeline reflects three trends: (1) the individual exploits are more device specific and operating system version specific; (2) exploits targeting vendors' customization grow steadily where the increase of other types of exploits slows down; and (3) memory corruption gradually becomes the primary approach to initiate exploitation.
- Is Part Of:
- Computers & security. Issue 76(2018)
- Journal:
- Computers & security
- Issue:
- Issue 76(2018)
- Issue Display:
- Volume 76, Issue 76 (2018)
- Year:
- 2018
- Volume:
- 76
- Issue:
- 76
- Issue Sort Value:
- 2018-0076-0076-0000
- Page Start:
- 71
- Page End:
- 91
- Publication Date:
- 2018-07
- Subjects:
- Android -- Mobile security -- Privilege escalation -- Exploit -- Survey
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2018.02.019 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 6812.xml