计算机与现代化

• 信息安全 • 上一篇    下一篇

针对安卓手机提权漏洞的新型防范模型设计与验证

  

  1. 武汉邮电科学研究院,湖北  武汉  430074
  • 收稿日期:2017-02-21 出版日期:2017-09-20 发布日期:2017-09-19
  • 作者简介:肖程望(1992-),男,湖南岳阳人,武汉邮电科学研究院硕士研究生,研究方向:通信与信息系统; 卢军(1964-),男,教授,博士,研究方向:通信与信息系统; 余力耕(1992-),男,硕士研究生,研究方向:通信与信息系统。

Design and Verification of New Defense Model for Android Mobile Phone Access Vulnerability

  1. Wuhan Research Institute of Posts and Telecommunications, Wuhan 430074, China
  • Received:2017-02-21 Online:2017-09-20 Published:2017-09-19

摘要: 目前,智能手机安全问题引起了人们高度的重视。木马作为一种隐蔽性、欺骗性很高的攻击手段,在该平台上不断蔓延,虽然受到广泛关注,但却没有很好的防范手段。在各种漏洞中,提权漏洞对于Android系统的安全威胁巨大,一旦攻击者有机会获得内核的内存地址,就能够通过关闭内核内存的写保护获得向内核内存写入恶意指令的权限,并实现下载木马病毒的目的。为应对这一漏洞,首先分析SEAndroid机制,并基于此机制提出一种新型的将内核加强和数据包过滤2种方法结合的提权漏洞防范模块,并通过实验对所提出的防范模块的有效性进行验证。

关键词: 安卓系统, 手机木马, 提权漏洞, 手机防火墙

Abstract: Today, smart phone security issues more and more arouse people’s attention. Trojan, as a highly hidden and deceptive attack means, has continuously spreading on the platform, although has been widespread concern, but there is no good way to suppress. The right to mention the loopholes for the Android system security threats is enormous. Once the attacker has the opportunity to leak through the kernel memory address of the kernel, he can close the kernel memory write protection to write the kernel memory to execute malicious commands permissions, and ultimately achieve the purpose of downloading Trojans. In order to deal with this vulnerability, we first analyze SEAndroid mechanism, and propose a kernel vulnerability prevention module combining kernel enhancement and packet filtering. Based on this mechanism, we verify the validity of the proposed prevention module.

Key words: Android system, mobile phone Trojans, elevate permissions loophole, mobile phone firewall

中图分类号: