An Evaluation of the Application ("App") Verification Service in Android 4.2
[Posted December 10, 2012 by corbet]
NCSU Professor Xuxian Jiang has posted
an assessment of
the application verification service featured in the Android 4.2
release. "
However, based on our evaluation results, we feel this
service is still nascent and there exists room for improvement.
Specifically, our study indicates that the app verification service mainly
uses an app's SHA1 value and the package name to determine whether it is
dangerous or potentially dangerous. This mechanism is fragile and can be
easily bypassed. It is already known that attackers can change with ease
the checksums of existing malware (e.g., by repackaging or mutating
it)."
(
Log in to post comments)