An Evaluation of the Application ("App") Verification Service in Android 4.2
[Posted December 10, 2012 by corbet]
An Evaluation of the Application ("App") Verification Service in Android 4.2
[Security] Posted Dec 10, 2012 17:58 UTC (Mon) by corbet
NCSU Professor Xuxian Jiang has posted an assessment of
the application verification service featured in the Android 4.2
release. "However, based on our evaluation results, we feel this
service is still nascent and there exists room for improvement.
Specifically, our study indicates that the app verification service mainly
uses an app's SHA1 value and the package name to determine whether it is
dangerous or potentially dangerous. This mechanism is fragile and can be
easily bypassed. It is already known that attackers can change with ease
the checksums of existing malware (e.g., by repackaging or mutating
it)."
Comments (none posted)