Computing Reviews
Today's Issue Hot Topics Search Browse Recommended My Account Log In
Recommended by Editor Recommended by Reviewer Recommended by Reader
Search
On lightweight mobile phone application certification
Enck W., Ongtang M., McDaniel P.  CCS 2009 (Proceedings of the 16th ACM Conference on Computer and Communications Security, Chicago, IL,  Nov 9-13, 2009) 235-245. 2009. Type: Proceedings
Date Reviewed: Jun 4 2010

Enck, Ongtang, and McDaniel present a methodology for certifying mobile phone applications during the installation process. During the installation process, the application is classified according to its behavior and possibly suspicious activities--for example, accessing a global positioning system (GPS) location and sending it over the Internet.

Android’s standard security decisions are primarily based on the application’s packet manifest--permissions may or may not be granted to applications, as requested. The authors defined the security rules using their Kirin Security Language; for instance, a rule may state that a certain application must not be debugged by another application. To validate their method, they analyzed existing applications and found that several applications, such as GPS-tracking programs, violate some of their rules and are thus classified as potentially dangerous. If installed in secret, tracking GPS locations and sending them over the Internet can be maliciously used for spying. The researchers also discovered some security flaws; for instance, in their early versions, Android applications created short message service (SMS) text messages that appeared to have been received over the cellular network when in fact they had been created locally.

In summary, Enck, Ongtang, and McDaniel present three main ideas in this paper: they describe a methodology for implementing additional security features in Android; they show how applications can be dynamically certified; and they provide and validate some rules that may be used to characterize the behavior of applications on mobile devices. This paper is for readers who are interested in “practical mobile phone security.”

Reviewer:  Edgar R. Weippl Review #: CR138070
  Editor Recommended
Featured Reviewer
 
 
Security and Protection (D.4.6 )
 
Would you recommend this review?
yes
no
Other reviews under "Security and Protection": Date
Effective implementation of the cell broadband engine isolation loader
Murase M., Shimizu K., Plouffe W., Sakamoto M.  CCS 2009 (Proceedings of the 16th ACM Conference on Computer and Communications Security, Chicago, Illinois,  Nov 9-13, 2009) 303-313, 2009. Type: Proceedings
Jun 17 2010
Building secure Web applications with automatic partitioning
Chong S., Liu J., Myers A., Qi X., Vikram K., Zheng L., Zheng X.  Communications of the ACM 52(2): 79-87, 2009. Type: Article
Jun 4 2010
Design and implementation of a tool for analyzing SELinux secure policy
Zhai G., Ma W., Tian M., Yang N., Liu C., Yang H.  ICIS 2009 (Proceedings of the 2nd International Conference on Interaction Sciences, Seoul, Korea,  Nov 24-26, 2009) 446-451, 2009. Type: Proceedings
Apr 1 2010
more...

E-Mail This Printer-Friendly
Send Your Comments
Contact Us
Reproduction in whole or in part without permission is prohibited.   Copyright © 2000-2010 Reviews.com
Terms of Use
| Privacy Policy