Nowadays, smartphones are ubiquitous in our daily lives. The number of users of these devices continues to grow worldwide. Currently, the tasks that smartphones are able to offer are almost comparable to those offered by conventional computers. However, it would be absurd to hold the comparison when it comes to security. Indeed, users of smartphones can access their email, their bank accounts and access their accounts of social networks. However, most people do not seem to realize they can be a victim of cyber attack threatening the three aspects of their data security: confidentiality, availability and integrity.
Several operating systems were introduced for smartphones. According to recent statistics, Android - launched by Google in 2007 - is the most widely used system in the smartphones market and is steadily gaining in popularity. This popularity is increasing not only among users but also among developers of mobile applications taking advantage of the openness of Android which is fully open source. Unfortunately, security in Android does not follow the same growth curve of the mobile operating system. In fact, the popularity of Android has made it become a prime target for cyber-attacks. Thus, the number of malicious applications has been multiplied in recent years. Contrary to what most smartphones users think, the impacts of these attacks have nothing less than the impacts caused by malware targeting conventional computers.
As part of this research, we were interested in a first step to characterize the different types of malicious applications targeting the Android operating system by introducing a new classification thereof based on the attack vectors they exploit. This classification would allow us to better understand the modus operandi of malicious applications targeting Android. We then propose new secure methods to develop applications for Android that we estimate capable of limiting the risk of malicious applications exploiting legitimate applications installed on the Android phone. The proposed methods are inspired by several security solutions for Android reported in the literature, with the advantage of not making changes to the Android system.
| Date | 27 Apr 2012 |
|---|
| Original language | French |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Jean-Marc Robert (Supervisor) |
|---|
Hadhiri, A. (Author),
Robert (Supervisor),
27 Apr 2012Student thesis: Master's thesis › Master in Engineering: Engineering