02.08.2016 Views

Android Security

AnSec2.0

AnSec2.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Mobile <strong>Security</strong><br />

Trusted app may be<br />

compromised as well<br />

Subverted Trusted App<br />

Attack Vectors (simplified)<br />

HTML/Plugin/MIME/etc<br />

Malformed SMS/MMS<br />

Any App<br />

Arbitrary Code Execution<br />

User carelessness<br />

Abuse system call<br />

Permission mistake<br />

Framework vulnerability<br />

Get system<br />

3 rd party daemon<br />

Insecure, root<br />

Get root<br />

Linux kernel APIs<br />

Unfettered access<br />

system_server runs all services<br />

in same address space!<br />

Kernel Code Exec<br />

Get Personal Data<br />

As of L, SELinux in<br />

Enforcing Mode provides<br />

another layer of protection<br />

Defeat SELinux<br />

(C) 2016 Jonathan Levin & Technologeeks.com - Share freely, but please cite source!<br />

Total Compromise

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!