security threat solutions
Android OS
Overview
● mobile context
● security challenges
● proposed solutions
Android
Open Handset Alliance
● Google
Open Source
● Base OS
● Application Middleware
● Java SDK
● System Application
Mobile
IDC: International Data Corporation
● 12/2012 Global Market Share Report
○ 68% Android OS
○ 19% Apple iOS
○ 5% RIM Blackberry OS
○ 3% MS Windows Phone
● Worldwide Quarterly Mobile Phone Tracker
○ 207.6 million units shipped 4Q12: 91.1% (APL+AND)
○ 70.2% increase from 4Q11
○ 722.4 million units shipped 2012: 87.6% (APL+AND)
○ 494.5 million units shipped 2011: 68.1% (APL+AND)
Market
GooglePlay
● ~700,000 applications
● 25 billion downloads
● 1.6 billion downloads/month
Apple
● ~700,000 applications
● 30 billion downloads
Security
iOS
● well designed
● largely resistant to attack
Windows
● ok for low level requirements
Blackberry
● considered most secure
Android
● considered least secure
Consumer
Enterprise
● Category 1: Routine
● Category 2: Important
● Category 3: Sensitive
● Category 4: Top-Secret
Solution
Cloud Based Reputation
● each app has unique ID
● store reputation for each app
● reputation classifications
○ good
○ unknown
○ bad
● pro: increases user awareness and power
● con: user's can't be trusted
Solution
OS Augmentation: Saint
● Secure Application INTeration
● governing framework
● policy enforcement
○ install-time
○ run-time
○ administrative
○ operational
● pro: integrated
● con: adoption
Conclusion
Android
● Largest target
● Greatest weakness
○ provenance
○ permissions
● Empower users
● OS Augmentation

Android security