IEEE Trans Cybern. 2016 Aug;46(8):1749-59. doi: 10.1109/TCYB.2016.2537649. Epub 2016 Apr 4.
Mobile systems are facing a number of application vulnerabilities that can be combined together and utilized to penetrate systems with devastating impact. When assessing the overall security of a mobile system, it is important to assess the security risks posed by each mobile applications (apps), thus gaining a stronger understanding of any vulnerabilities present. This paper aims at developing a three-layer framework that assesses the potential risks which apps introduce within the Android mobile systems. A Bayesian risk graphical model is proposed to evaluate risk propagation in a layered risk architecture. By integrating static analysis, dynamic analysis, and behavior analysis in a hierarchical framework, the risks and their propagation through each layer are well modeled by the Bayesian risk graph, which can quantitatively analyze risks faced to both apps and mobile systems. The proposed hierarchical Bayesian risk graph model offers a novel way to investigate the security risks in mobile environment and enables users and administrators to evaluate the potential risks. This strategy allows to strengthen both app security as well as the security of the entire system.
移动系统面临着许多应用程序漏洞,这些漏洞可以组合在一起,并利用它们来对系统进行渗透,从而造成巨大的影响。在评估移动系统的整体安全性时,评估每个移动应用程序(apps)所带来的安全风险非常重要,从而更好地了解存在的任何漏洞。本文旨在开发一个三层框架,评估应用程序在 Android 移动系统中引入的潜在风险。提出了一种贝叶斯风险图形模型来评估分层风险架构中的风险传播。通过在层次框架中集成静态分析、动态分析和行为分析,贝叶斯风险图很好地对每个层的风险及其传播进行建模,从而可以对应用程序和移动系统面临的风险进行定量分析。所提出的分层贝叶斯风险图模型为研究移动环境中的安全风险提供了一种新方法,并使用户和管理员能够评估潜在风险。这种策略可以增强应用程序的安全性以及整个系统的安全性。