Firewall-based Solution for Preventing Privilege Escalation Attacks in Android

International Journal of Computer Networks and Communications Security · 2014

In this paper, we are proposing a Firewall-based solution for protecting Android operating systems against privilege escalation attacks, mainly, confused deputy attacks and collusion attacks.The proposed Firewall protects the applications that have critical privilege permission.Any other applications without the critical permission will not be able to call protected applications via privilege escalation attacks.Since the Internet is the door of attack, we consider the permission to access Internet as a critical permission.As such, any application cannot access the Internet directly or indirectly, through privilege escalation, without confirmation of the user disallowing invulnerable leakage of private data.The proposed solution allows also protection to different critical permissions through the creation of multi-critical protection zones.We implemented the multi-critical protection zones by selecting READ_CONTACTS permission and INTERNET permission as critical permissions and the applications having one of these permission or both, they will be protected by our firewall against the privilege escalation attacks.The efficiency and effectiveness of the proposed solution are evaluated in this paper along with the imposed overhead.The evaluation includes the Android with one zone firewall and with two zones firewall.

Read the paper · More papers on PaperTik