Featured Research

from universities, journals, and other organizations

Android security weaknesses caused by performance design identified

Date:
June 19, 2014
Source:
Georgia Institute of Technology
Summary:
Researchers have identified a weakness in one of Android’s security features. The research identifies an Android performance feature that weakens a software protection called Address Space Layout Randomization (ASLR), leaving software components vulnerable to attacks that bypass the protection.

Georgia Tech researchers have identified a weakness in one of Android's security features and will present their work at Black Hat USA 2014, which will be held August 6-7 in Las Vegas.

The research, titled Abusing Performance Optimization Weaknesses to Bypass ASLR, identifies an Android performance feature that weakens a software protection called Address Space Layout Randomization (ASLR), leaving software components vulnerable to attacks that bypass the protection. The work is aimed at helping security practitioners identify and understand the future direction of such attacks.

The work was conducted at the Georgia Tech Information Security Center (GTISC) by Ph.D. students Byoungyoung Lee and Yeongjin Jang and research scientist Tielei Wang, and reveals that the introduction of performance optimization features can inadvertently harm the security guarantees of an otherwise vetted system. In addition to describing how vulnerabilities originate from such designs, they demonstrate real attacks that exploit them.

"To optimize object tracking for some programming languages, interpreters for the languages may leak address information," said Lee, lead researcher for the effort. "As a concrete example, we'll demonstrate how address information can be leaked in the Safari web browser by simply running some JavaScript."

Bypassing ASLR using hash table leaks was previously believed to be obsolete due to its complexity. By exhaustively investigating various language implementations and presenting concrete attacks, the research aims to show that the concern is still valid.

"As part of our talk, we'll present an analysis of the Android Zygote process creation model," Lee said. "The results show that Zygote weakens ASLR as all applications are created with largely identical memory layouts. To highlight the issue, we'll show two different ASLR bypass attacks using real applications -- Google Chrome and VLC Media Player."

The Black Hat Briefings were created approximately 16 years ago to provide computer security professionals a place to learn the very latest in information security risks, research and trends. Presented by the brightest in the industry, the briefings cover everything from critical information infrastructure to widely used enterprise computer systems to the latest InfoSec research and development. These briefings are vendor-neutral, allowing the presenters to speak candidly about the real problems and potential solutions across both the public and private sectors.


Story Source:

The above story is based on materials provided by Georgia Institute of Technology. Note: Materials may be edited for content and length.


Cite This Page:

Georgia Institute of Technology. "Android security weaknesses caused by performance design identified." ScienceDaily. ScienceDaily, 19 June 2014. <www.sciencedaily.com/releases/2014/06/140619144618.htm>.
Georgia Institute of Technology. (2014, June 19). Android security weaknesses caused by performance design identified. ScienceDaily. Retrieved July 24, 2014 from www.sciencedaily.com/releases/2014/06/140619144618.htm
Georgia Institute of Technology. "Android security weaknesses caused by performance design identified." ScienceDaily. www.sciencedaily.com/releases/2014/06/140619144618.htm (accessed July 24, 2014).

Share This




More Science & Society News

Thursday, July 24, 2014

Featured Research

from universities, journals, and other organizations


Featured Videos

from AP, Reuters, AFP, and other news services

Boeing Ups Outlook on 52% Profit Jump

Boeing Ups Outlook on 52% Profit Jump

Reuters - Business Video Online (July 23, 2014) Commercial aircraft deliveries rose seven percent at Boeing, prompting the aerospace company to boost full-year profit guidance- though quarterly revenues missed analyst estimates. Bobbi Rebell reports. Video provided by Reuters
Powered by NewsLook.com
Thousands Who Can't Afford Medical Care Flock to Free US Clinic

Thousands Who Can't Afford Medical Care Flock to Free US Clinic

AFP (July 23, 2014) America may be the world’s richest country, but in terms of healthcare, the World Health Organisation ranks it 37th. Thousands turned out for a free clinic run by "Remote Area Medical" with a visit from the Governor of Virginia. Duration: 2:40 Video provided by AFP
Powered by NewsLook.com
Six Indicted in StubHub Hacking Scheme

Six Indicted in StubHub Hacking Scheme

AP (July 23, 2014) Six people were indicted Wednesday in an international ring that took over more than 1,000 StubHub users' accounts and fraudulently bought tickets that were then resold. (July 23) Video provided by AP
Powered by NewsLook.com
9/11 Commission Members Warn of Terror "fatigue" Among American Public

9/11 Commission Members Warn of Terror "fatigue" Among American Public

Reuters - US Online Video (July 22, 2014) Ten years after releasing its initial report, members of the 9/11 Commission warn of the "waning sense of urgency" in combating terrorists attacks. Mana Rabiee reports. Video provided by Reuters
Powered by NewsLook.com

Search ScienceDaily

Number of stories in archives: 140,361

Find with keyword(s):
Enter a keyword or phrase to search ScienceDaily for related topics and research stories.

Save/Print:
Share:

Breaking News:
from the past week

In Other News

... from NewsDaily.com

Science News

Health News

Environment News

Technology News



Save/Print:
Share:

Free Subscriptions


Get the latest science news with ScienceDaily's free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Get Social & Mobile


Keep up to date with the latest news from ScienceDaily via social networks and mobile apps:

Have Feedback?


Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
Mobile: iPhone Android Web
Follow: Facebook Twitter Google+
Subscribe: RSS Feeds Email Newsletters
Latest Headlines Health & Medicine Mind & Brain Space & Time Matter & Energy Computers & Math Plants & Animals Earth & Climate Fossils & Ruins