Discovering Authentication Credentials in Volatile Memory of Android Mobile Devices

Discovering Authentication Credentials in Volatile Memory of Android Mobile Devices
复制标题

DOI:
10.1007/978-3-642-37437-1_15
复制
发表时间:
2013-04
期刊:
--
影响因子:
--
通讯作者:
Dimitris Apostolopoulos;Giannis Marinakis;Christoforos Ntantogian;C. Xenakis
Dimitris Apostolopoulos;Giannis Marinakis;Christoforos Ntantogian;C. Xenakis
中科院分区:
其他
文献类型:
--
作者:
Dimitris Apostolopoulos;Giannis Marinakis;Christoforos Ntantogian;C. Xenakis

文献摘要

被引文献

相似文献

本文研究了Android移动的设备的易失性内存中的身份验证凭据是否可以使用免费提供的工具发现。我们为每个应用程序执行的实验包括两个不同的集合:在第一个集合中,我们的目标是检查我们是否可以从移动终端的内存转储中恢复我们自己提交的凭据。在第二组实验中,目标是找到可以指示凭据在Android设备的内存转储中的位置的模式。结果显示,大多数Android应用程序都容易受到凭据发现的影响,即使是在安全性至关重要的应用程序中,例如网络银行和密码管理器应用程序。
This paper investigates whether authentication credentials in the volatile memory of Android mobile devices can be discovered using freely available tools. The experiments that we carried out for each application included two different sets: In the first set, our goal was to check if we could recover our own submitted credentials from the memory dump of the mobile device. In the second set of experiments, the goal was to find patterns that can indicate where the credentials are located in a memory dump of an Android device. The results revealed that the majority of the Android applications are vulnerable to credentials discovery even in case of applications that their security is critical, such as web banking and password manager applications.