Towards Taming Privilege-Escalation Attacks on Android

Towards Taming Privilege-Escalation Attacks on Android
复制标题

DOI:
--
复制
发表时间:
2012
期刊:
影响因子:
13.3
通讯作者:
Sven Bugiel;Lucas Davi;A. Dmitrienko;Thomas Fischer;A. Sadeghi;Bhargava Shastry
Sven Bugiel;Lucas Davi;A. Dmitrienko;Thomas Fischer;A. Sadeghi;Bhargava Shastry
中科院分区:
材料科学1区
文献类型:
--
作者:
Sven Bugiel;Lucas Davi;A. Dmitrienko;Thomas Fischer;A. Sadeghi;Bhargava Shastry

文献摘要

被引文献

相似文献

在过去几年中,安卓的安全框架一直是一个颇具吸引力的研究课题。研究表明,安卓容易受到应用层权限提升攻击,比如“糊涂代理”攻击,以及近期出现的应用程序勾结攻击。虽然大多数已提出的方法旨在解决“糊涂代理”攻击,但仍然没有一种解决方案能够同时应对勾结攻击。在本文中,我们研究了为安卓设计并实现一个实用的安全框架以防范“糊涂代理”和勾结攻击的问题。我们认识到,挫败勾结攻击需要一种以系统为中心的解决方案,而非依赖应用程序的策略执行。为了支持我们的设计决策,我们对安卓系统行为(结合流行应用程序)进行了启发式分析,以识别攻击模式、对不同的敌手模型进行分类,并指出需要应对的挑战。然后,我们提出了一种在多个层面上对应用程序之间的通信通道进行以系统为中心且由策略驱动的运行时监控的解决方案:1)在中间件层面,我们控制应用程序之间的进程间通信(IPC)以及通过安卓系统组件进行的间接通信。此外,受QUIRE方法的启发,我们在进程间通信之间建立语义链接,并使引用监视器能够验证调用链;2)在内核层面,我们对文件系统(包括Unix域套接字)和本地互联网套接字实现强制访问控制。为了实现运行时动态的底层策略执行,我们在内核和中间件之间提供了一个回调通道。最后,我们评估了我们的框架在已知的“糊涂代理”和勾结攻击方面的效率和有效性,并讨论了未来的研究方向。
Android's security framework has been an appealing subject of research in the last few years. Android has been shown to be vulnerable to application-level privilege escalation attacks, such as confused deputy attacks, and more recently, attacks by colluding applications. While most of the proposed approaches aim at solving confused deputy attacks, there is still no solution that simultaneously addresses collusion attacks. In this paper, we investigate the problem of designing and implementing a practical security framework for Android to protect against confused deputy and collusion attacks. We realize that defeating collusion attacks calls for a rather system-centric solution as opposed to application-dependent policy enforcement. To support our design decisions, we conduct a heuristic analysis of Android's system behavior (with popular apps) to identify attack patterns, classify different adversary models, and point out the challenges to be tackled. Then we propose a solution for a system-centric and policy-driven runtime monitoring of communication channels between applications at multiple layers: 1) at the middleware we control IPCs between applications and indirect communication via Android system components. Moreover, inspired by the approach in QUIRE, we establish semantic links between IPCs and enable the reference monitor to verify the call-chain; 2) at the kernel level we realize mandatory access control on the file system (including Unix domain sockets) and local Internet sockets. To allow for runtime, dynamic low-level policy enforcement, we provide a callback channel between the kernel and the middleware. Finally, we evaluate the efficiency and effectiveness of our framework on known confused deputy and collusion attacks, and discuss future directions.