Connecting to LinkedIn...

W1siziisijiwmtuvmdqvmtuvmdgvntqvmzgvnzi1l01ptlrbu0hfqkxpr19vtljftkrfukvex0lnqudfx3jlc2l6zwrfyw5kx3jlbmrlcmvklmpwzyjdlfsiccisinrodw1iiiwimtkymhgxmjuwiyjdxq

Blog

Georgia Tech research identifies Android security weaknesses caused by performance design

20/06/2014 by

W1siziisijiwmtqvmtavmjgvmtuvmzyvntgvmza0l2zpbguixsxbinailcj0ahvtyiisijywmhg0mdbcdtawm2uixv0

Georgia Tech researchers have identified a weakness in one of Android’s security features and will present their work at Black Hat USA 2014, which will be held August 6-7 in Las Vegas. The research, titled Abusing Performance Optimisation Weaknesses to Bypass ASLR, identifies an Android performance feature that weakens a software protection called Address Space Layout Randomization (ASLR), leaving software components vulnerable to attacks that bypass the protection. The work is aimed at helping security practitioners identify and understand the future direction of such attacks.

The work was conducted at the Georgia Tech Information Security Center (GTISC) by Ph.D. students Byoungyoung Lee and Yeongjin Jang and research scientist Tielei Wang, and reveals that the introduction of performance optimisation features can inadvertently harm the security guarantees of an otherwise vetted system. In addition to describing how vulnerabilities originate from such designs, they demonstrate real attacks that exploit them.

“To optimize object tracking for some programming languages, interpreters for the languages may leak address information,” said Lee, lead researcher for the effort. “As a concrete example, we’ll demonstrate how address information can be leaked in the Safari web browser by simply running some JavaScript.”

This article has been extracted from http://esciencenews.com, please click on this link to read the article in full http://esciencenews.com/articles/2014/06/19/georgia.tech.research.identifies.android.security.weaknesses.caused.performance.design

Montash is a multi-award winning, global IT recruitment firm. Specialising in permanent and contract positions across mid-senior appointments which cover a wide range of industry sectors and IT functions, including:

ERP, BI & Data, Information Security, IT Architecture & Strategy, Scientific Technologies, Demand IT and Business Engagement, Digital and E-commerce, Infrastructure and Service Delivery, Project and Programme Delivery.

With offices based in London, Montash has completed assignments in over 30 countries and has appointed technical professionals from board level to senior and mid-management in permanent and contract roles.

Bypassing ASLR using hash table leaks was previously believed to be obsolete due to its complexity. By exhaustively investigating various language implementations and presenting concrete attacks, the research aims to show that the concern is still valid.

comments powered by Disqus

Social Stream

Latest News

W1siziisijiwmtcvmdyvmtkvmtavndkvmtavntuvc2h1dhrlcnn0b2nrxzqymzk2mjg2ni5qcgcixsxbinailcj0ahvtyiisijm4mhgxmdajil1d

Long Term Transition, Not Long Term Tradition...

2017-06-20 09:00:00 +0100

It seems odd that while 88% of businesses are undergoing some kind of digital transformation[1], only 25%[2] of them have a clear understanding of their digital transformation journey. So what's driving so many businesses to pursue digital with such recklessness? Broadly speaking, the reason is simply the unprecedented rate of change in digital solutions and services. As we ride the digital tidal wave, consumers and employees change their expectations, ...

W1siziisijiwmtcvmdyvmtmvmtavmjqvmjuvodcxl3nodxr0zxjzdg9ja181njewnja3mzmuanbnil0swyjwiiwidgh1bwiilcizodb4mtawiyjdxq

How Great Leaders Cultivate Great Teams

2017-06-13 12:00:00 +0100

There's a difference between being a boss and being a leader. Leaders know how to inspire the best from their teams to achieve industry-leading results. For our latest blog, we spoke to our Managing Director, Roy Dungworth, to discover how businesses can create a culture that inspires great people to do great things together. Success in business doesn't begin and end with great leadership. Great leaders inspire their teams to want to do more and be bett...