Can We Trust the Phone Vendors? Comprehensive Security Measurements on the Android Firmware Ecosystem

固件 计算机科学 Android(操作系统) 操作系统 软件 计算机安全 万维网
作者
Qinsheng Hou,Wenrui Diao,Yanhao Wang,C. Mao,Lingyun Ying,Song Liu,Xiaofeng Liu,Yuanzhi Li,Shanqing Guo,Meining Nie,Haixin Duan
出处
期刊:IEEE Transactions on Software Engineering [IEEE Computer Society]
卷期号:49 (7): 3901-3921
标识
DOI:10.1109/tse.2023.3275655
摘要

Android is the most popular smartphone platform with over 85% market share. Its success is built on openness, and phone vendors can utilize the Android source code to make customized products with unique software/hardware features. On the other hand, the fragmentation and customization of Android also bring many security risks that have attracted the attention of researchers. Many efforts were put in to investigate the security of customized Android firmware. However, most of the previous works focus on designing efficient analysis tools or analyzing particular aspects of the firmware. There still lacks a panoramic view of Android firmware ecosystem security and the corresponding understandings based on large-scale firmware datasets. In this work, we made a large-scale comprehensive measurement of the Android firmware ecosystem security. Our study is based on 8,325 firmware images from 153 vendors and 813 Android-related CVEs, which is the largest Android firmware dataset ever used for security measurements. In particular, our study followed a series of research questions, covering vulnerabilities, patches, security updates, and pre-installed apps. To automate the analysis process, we designed a framework, AndScanner+ , to complete firmware crawling, firmware parsing, patch analysis, and app analysis. Through massive data analysis and case explorations, several interesting findings are obtained. For example, the patch delay and missing issues are widespread in Android firmware images, say 31.4% and 5.6% of all images, respectively. The latest images of several phones still contain vulnerable pre-installed apps, and even the corresponding vulnerabilities have been publicly disclosed. In addition to data measurements, we also explore the causes behind these security threats through case studies and demonstrate that the discovered security threats can be converted into exploitable vulnerabilities. There are 46 new vulnerabilities found by AndScanner+ , 36 of which have been assigned CVE/CNVD IDs. This study provides much new knowledge of the Android firmware ecosystem with a deep understanding of software engineering security practices.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
FashionBoy应助liuqi6767采纳,获得10
刚刚
泊林发布了新的文献求助10
1秒前
1秒前
1秒前
拓木幸子完成签到,获得积分10
2秒前
个性的紫菜应助苗苗采纳,获得100
2秒前
2秒前
3秒前
3秒前
3秒前
阿梨完成签到,获得积分10
3秒前
进步发布了新的文献求助10
3秒前
4秒前
RSC发布了新的文献求助10
4秒前
科研通AI6应助叶公子采纳,获得10
5秒前
yujia完成签到,获得积分10
6秒前
7秒前
7秒前
7秒前
传奇3应助草莓饼干采纳,获得10
7秒前
滕侑林发布了新的文献求助10
7秒前
8秒前
8秒前
8秒前
进击的研狗完成签到 ,获得积分10
8秒前
科研通AI2S应助sciress采纳,获得10
8秒前
申左一发布了新的文献求助10
9秒前
丘比特应助HughWang采纳,获得10
9秒前
量子星尘发布了新的文献求助10
9秒前
zhul09完成签到,获得积分10
9秒前
9秒前
stephanie_han完成签到,获得积分10
9秒前
尊敬的书桃完成签到 ,获得积分20
9秒前
wufel2完成签到,获得积分0
10秒前
10秒前
11秒前
无情的面包完成签到,获得积分10
11秒前
Mely0203发布了新的文献求助10
11秒前
主见发布了新的文献求助10
11秒前
11秒前
高分求助中
计划经济时代的工厂管理与工人状况(1949-1966)——以郑州市国营工厂为例 500
INQUIRY-BASED PEDAGOGY TO SUPPORT STEM LEARNING AND 21ST CENTURY SKILLS: PREPARING NEW TEACHERS TO IMPLEMENT PROJECT AND PROBLEM-BASED LEARNING 500
The Pedagogical Leadership in the Early Years (PLEY) Quality Rating Scale 410
Stackable Smart Footwear Rack Using Infrared Sensor 300
Modern Britain, 1750 to the Present (第2版) 300
Writing to the Rhythm of Labor Cultural Politics of the Chinese Revolution, 1942–1976 300
Lightning Wires: The Telegraph and China's Technological Modernization, 1860-1890 250
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 生物化学 物理 纳米技术 计算机科学 内科学 化学工程 复合材料 物理化学 基因 催化作用 遗传学 冶金 电极 光电子学
热门帖子
关注 科研通微信公众号,转发送积分 4603838
求助须知:如何正确求助?哪些是违规求助? 4012374
关于积分的说明 12423535
捐赠科研通 3692896
什么是DOI,文献DOI怎么找? 2035955
邀请新用户注册赠送积分活动 1069072
科研通“疑难数据库(出版商)”最低求助积分说明 953559