Securing the mobile environment

Najim Ammari, Almokhtar Ait El Mrabti, Anas Abou El Kalam, Abdellah Ait Ouahman · 2017

The growth of the smartphone 1 market broke the record in recent years, smartphones have become more robust tools in terms of storage capacity and computing power, effective tools for business to improve productivity, and daily tools for many people due to the various services they offer and allow to end users to perform multiple tasks and be always updated on the move. This has made it a favorite target for malicious applications that specifically attack their personal and professional data. To overcome this problem, mobile platforms have set up a security system based on the permissions model; the user decides whether to validate the permissions requested by an application before installation, or to abort the installation. In case the user needs to install an application, and that application requests unjustified permissions, this represents a particularly troublesome weakness. In this study, we are going to handle the case of the Open Source Android platform, currently managed by Google. Despite the efforts to create a scalable and secure operating system, Google is not able to process the information of user privacy. Any Android application can discreetly retrieve sensitive data from the smartphone without notifying the user. In this paper, we propose a firewall Anti-Leak of Sensitive Data on Smartphone (ALSDS), allowing reliable protection against leakage of sensitive personal and professional data, and it allows providing notifications to the user. This integrated solution to the mobile operating system is based on automated analysis of markets; it allows blocking applications query on the sensitive data while ensuring their proper functioning.

Read the paper · More papers on PaperTik