Software Assurance Challenges Of Smartphones (Android)


Android has in place a very specific permissions and security system based around manifest file declarations which allow or restrict applications from accessing various device capabilities.

Software Assurance  Challenges Of Smartphones (Android)
Software Assurance  Challenges

Overall Idea
  • Software assurance is always a function of time,
  • Software assurance is a non-boundable problem, except in rare cases, and only partially, such as embedded systems.
  • Software today is increasingly less viewed as a product and more viewed as a service , and therefore service assurance is vital to understand.
Security Design Goals and Objectives
End-to-End Security that encompasses ALL Participating Entities
  • Device Security
  • Application Security
  • Application Store Security
  • Provisioning Security
  • Identity Management of Users & Applications
  • Security Customization of each device for the Mission
  • Device and Application Security tailored to the Mission Objectives
  • Automatic & Flexible Provisioning & Phone Reconfiguration

Multiple Levels of Security
Application Vetting & Testing
  1. Device Lock-down and Encryption of ALL Dataand Communications
  2. Enforcement of Security Policies in the AndroidFramework
  3. Second-level Defenses placed in the Android Linux Kernel
  • Prevent Attacks that bypass Android Security Framework
  • Android has Inherited some (if not all) of the LinuxVulnerabilities
  • Java Native Interface to Linux Libraries a potential
  • Avenue for Exploitation


Category Article , , , ,

What's on Your Mind...

Random Posts

Powered by Blogger.