Abstract
dc:description.abstract<p>The open nature of Android ecosystem has naturally laid the foundation for a highly fragmented operating system. In fact, the official AOSP versions have been aggressively customized into thousands of system images by everyone in the customization chain, such as device manufacturers, vendors, carriers, etc. If not well thought-out, the customization process could result in serious security problems. This dissertation performs a systematic investigation of Android customization’ inconsistencies with regards to security aspects at various Android layers.</p> <p>It brings to light new vulnerabilities, never investigated before, caused by the under-regulated and complex Android customization. It first describes a novel vulnerability "Hare" and proves that it is security critical and extensive affecting devices from major vendors. A new tool is proposed to detect the Hare problem and to protect affected devices. This dissertation further discovers security configuration changes through a systematic differential analysis among custom devices from different vendors and demonstrates that they could lead to severe vulnerabilities if introduced unintentionally.</p>
Degree
thesis:*- Name thesis:degree_name
- Doctor of Philosophy (PhD)
- Level thesis:degree_level
- Dissertation
- Discipline thesis:degree_discipline
- Electrical Engineering and Computer Science
- Year
- 2016
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Aafer, Yousra
- Contributors dc:contributor
-
- Wenliang Du
Subjects
dc:subject × 6Identifiers
dc:identifier.*- Repository record dc:identifier
- https://surface.syr.edu/etd/635
- OAI identifier oai:identifier
- oai:surface.syr.edu:etd-1635