Discovering Authentication Credentials in Volatile Memory of Android Mobile Devices
Discovering Authentication Credentials in Volatile Memory of Android Mobile Devices
复制标题
DOI:
10.1007/978-3-642-37437-1_15
复制
发表时间:
2013-04
期刊:
影响因子:
--
通讯作者:
Dimitris Apostolopoulos;Giannis Marinakis;Christoforos Ntantogian;C. Xenakis
中科院分区:
文献类型:
--
作者:
Dimitris Apostolopoulos;Giannis Marinakis;Christoforos Ntantogian;C. Xenakis
This paper investigates whether authentication credentials in the volatile memory of Android mobile devices can be discovered using freely available tools. The experiments that we carried out for each application included two different sets: In the first set, our goal was to check if we could recover our own submitted credentials from the memory dump of the mobile device. In the second set of experiments, the goal was to find patterns that can indicate where the credentials are located in a memory dump of an Android device. The results revealed that the majority of the Android applications are vulnerable to credentials discovery even in case of applications that their security is critical, such as web banking and password manager applications.