Главная
Study mode:
on
1
Intro
2
Motivation (cont'd)
3
Contributions
4
Unix domain sockets
5
Threat model
6
ABSTRACT is the default
7
Authentication is needed
8
Highlights
9
Apps using Unix sockets (Q1)
10
Socket address analysis (Q2)
11
Authentication analysis (03)
12
Implementation
13
Overview
14
Real-world usage
15
Identified libraries
16
Weak authentication
17
Strong authentications
18
Common mistakes
19
Case study: KingRoot
20
Mitigations (cont'd)
21
Summary
22
Demos
Description:
Explore a conference talk from CCS 2016 examining the security implications of Android Unix domain sockets misuse. Delve into the research conducted by experts from the University of Michigan and University of California, Riverside, as they present their findings on potential vulnerabilities in Android applications. Learn about Unix domain sockets, threat models, and authentication methods in Android systems. Discover the researchers' analysis of socket address usage, authentication practices, and common mistakes made by developers. Gain insights into real-world examples, including a case study on KingRoot, and understand proposed mitigations to enhance Android security. Conclude with a summary and demonstrations that illustrate the practical impact of these security issues.

The Misuse of Android Unix Domain Sockets and Security Implications

Association for Computing Machinery (ACM)
Add to list