25th USENIX Security Symposium has ended
Back To Schedule
Friday, August 12 • 5:30pm - 6:00pm
Harvesting Inconsistent Security Configurations in Custom Android ROMs via Differential Analysis

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Android customization offers substantially different experiences and rich functionalities to users. Every party in the customization chain, such as vendors and carriers, modify the OS and the pre-installed apps to tailor their devices for a variety of models, regions, and custom services. However, these modifications do not come at no cost. Several existing studies demonstrate that modifying security configurations during the customization brings in critical security vulnerabilities. Albeit these serious consequences, little has been done to systematically study how Android customization can lead to security problems, and how severe the situation is. In this work, we systematically identified security features that, if altered during the customization, can introduce potential risks. We conducted a large scale differential analysis on 591 custom images to detect inconsistent security features. Our results show that these discrepancies are indeed prevalent among our collected images. We have further identified several risky patterns that warrant further investigation. We have designed attacks on real devices and confirmed that these inconsistencies can indeed lead to actual security breaches.

Friday August 12, 2016 5:30pm - 6:00pm PDT
Zilker Ballroom 2

Attendees (2)