Root exploits take over the system administration functions of an operating system, such as Android. A successful Android root exploit effectively gives hackers unfettered control of a user's smartphone.
The new security tool is called Practical Root Exploit Containment (PREC). It refines an existing technique called anomaly detection, which compares the behavior of a downloaded smartphone application (or app), such as Angry Birds, with a database of how the application should be expected to behave.
When deviations from normal behavior are detected, PREC analyzes them to determine if they are malware or harmless "false positives." If PREC determines that an app is attempting root exploit, it effectively contains the malicious code and prevents it from being executed.
"Anomaly detection isn't new, and it has a problematic history of reporting a lot of false positives," says Dr. Will Enck, an assistant professor of computer science at NC State and co-author of a paper on the work. "What sets our approach apart is that we are focusing solely on C code, which is what most -- if not all -- Android root exploits are written in."
"Taking this approach has significantly driven down the number of false positives," says Dr. Helen Gu, an associate professor of computer science at NC State and co-author of the paper. "This reduces disturbances for users and makes anomaly detection more practical."
The researchers are hoping to work with app vendors, such as Google Play, to establish a database of normal app behavior.
Most app vendors screen their products for malware, but malware programmers have developed techniques for avoiding detection -- hiding the malware until users have downloaded the app and run it on their smartphones.
The NC State research team wants to take advantage of established vendor screening efforts to create a database of each app's normal behavior. This could be done by having vendors incorporate PREC software into their app assessment processes. The software would take the app behavior data and create an external database, but would not otherwise affect the screening process.
"We have already implemented the PREC system and tested it on real Android devices," Gu says. "We are now looking for industry partners to deploy PREC, so that we can protect Android users from root exploits."
The paper, "PREC: Practical Root Exploit Containment for Android Devices," will be presented at the Fourth ACM Conference on Data and Application Security and Privacy being held March 3-5 in San Antonio, Texas. Lead author of the paper is former NC State graduate student Tsung-Hsuan Ho. The paper was co-authored by Daniel Dean, a Ph.D. student in Gu's lab at NC State.
The work was supported by the National Security Agency; U.S. Army Research Office grant W911NF-10-1-0273; National Science Foundation grants CNS-1149445, CNS-1253346, and CNS-1222680; IBM Faculty Awards and Google Research Awards.
Cite This Page:
North Carolina State University. "New technique targets C code to spot, contain malware attacks." ScienceDaily. ScienceDaily, 4 March 2014.
Emergency call centers in the US are suffering a rise in TDoS (telephony denial of service) attacks, according to an alert issued recently by the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI).
The agencies are speculating that these businesses and emergency services in particular are being targeted because phone lines are crucial to their operations.
Call now someone is looking for you.Call now and we will settle this.Somebody talking down on you, look for themHey y is someone calln me and lookn for u n askn me where r u at n where u live heres tha # tell then to stop calln me
The truth is that these hacking stories aren't really describing a technological problem. They're describing a human problem. It's remarkably easy to dupe someone into clicking on a link or opening an attachment in an email, and for their computer to become compromised.
While the attacks appeared to be targeted to a small number of sites, there is no obvious link between the victims.
The Metropolitan Police have arrested two men and a woman in connection with a spate of computer attacks that have held innocent internet users to ransom.
Their methods were both more sophisticated and determined than the average cybercriminals, the report noted.
Attacks against the websites of leading banks in the United States have the banking and financial services industry on edge.
Wells Fargo used its Twitter account to apologize for service interruptions on Wednesday and said it was working to "quickly resolve this issue." Most of the targeted banks were back online and operational Thursday.
Online scammers are using a recent email from Microsoft as bait in a widespread spam campaign that exploits vulnerabilities in Oracle’s Java software to install malicious programs on vulnerable systems.
The malicious websites in question are running the latest versions of the Blackhole Exploit Kit, a kind of Swiss Army Knife for compromising vulnerable computers.
iFrames and script tags are being used by malicious hackers to serve up drive-by internet attacks, silently and invisibly.
Two teenagers have been arrested in Norway in connection with a series of distributed denial-of-service (DDoS) attacks against websites in the country, and elsewhere around the world.
The success of phones running Google's Android software has meant cyber-attacks have risen 472 per cent in just three months - from cyber-spying apps to apps that add to your phone bill
HTC's Evo 4G handset runs Google's popular Android software: But the internet giant's anything-goes approach to its app store has led to an increase in cyber attacks on users