Kernel Modification APT Attack Detection in Android

dc.contributor.authorAnto, A.
dc.contributor.authorRao, R.S.
dc.contributor.authorPais, A.R.
dc.date.accessioned2026-02-06T06:38:54Z
dc.date.issued2017
dc.description.abstractAndroid is one of the most secure and widely used operating systems for the mobile platform. Most of the Android devices have the functionality for rooting and installing new custom ROMs and kernels in the device. This feature of the Android devices makes it vulnerable to the kernel-modification advanced persistent threat attack (APT). This type of APT attacks cannot be detected by using existing tools and methods. This paper presents the implementation details of a kernel-modification APT attack performed on an android device and proposes a new method for detecting the same. The proposed system uses control flow analysis of the kernel binary code for detecting APT. In control flow analysis the control flow graph of the genuine kernel is compared with the control flow graph of the device-kernel and detects the APT based on signatures. © 2017, Springer Nature Singapore Pte Ltd.
dc.identifier.citationCommunications in Computer and Information Science, 2017, Vol.746, , p. 236-249
dc.identifier.issn18650929
dc.identifier.urihttps://doi.org/10.1007/978-981-10-6898-0_20
dc.identifier.urihttps://idr.nitk.ac.in/handle/123456789/31960
dc.publisherSpringer Verlag service@springer.de
dc.subjectAdvanced persistent threat
dc.subjectAndroid kernel
dc.subjectAndroid security
dc.subjectAPT detection
dc.subjectOperating system
dc.titleKernel Modification APT Attack Detection in Android

Files