Title
Harvesting Inconsistent Security Configurations In Custom Android Roms Via Differential Analysis
Abstract
Android customization offers substantially different experiences and rich functionalities to users. Every party in the customization chain, such as vendors and carriers, modify the OS and the pre-installed apps to tailor their devices for a variety of models, regions, and custom services. However, these modifications do not come at no cost. Several existing studies demonstrate that modifying security configurations during the customization brings in critical security vulnerabilities. Albeit these serious consequences, little has been done to systematically study how Android customization can lead to security problems, and how severe the situation is. In this work, we systematically identified security features that, if altered during the customization, can introduce potential risks. We conducted a large scale differential analysis on 591 custom images to detect inconsistent security features. Our results show that these discrepancies are indeed prevalent among our collected images. We have further identified several risky patterns that warrant further investigation. We have designed attacks on real devices and confirmed that these inconsistencies can indeed lead to actual security breaches.
Year
Venue
Field
2016
PROCEEDINGS OF THE 25TH USENIX SECURITY SYMPOSIUM
Android (operating system),Warrant,Computer security,Computer science,Differential analysis,Personalization,Vulnerability
DocType
Citations 
PageRank 
Conference
4
0.44
References 
Authors
22
3
Name
Order
Citations
PageRank
Yousra Aafer126413.36
Xiao Zhang2692.93
wenliang du34906241.77