{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T12:46:26Z","timestamp":1725453986589},"publisher-location":"Berlin, Heidelberg","reference-count":41,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642337031"},{"type":"electronic","value":"9783642337048"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-33704-8_2","type":"book-chapter","created":{"date-parts":[[2012,10,9]],"date-time":"2012-10-09T13:12:43Z","timestamp":1349788363000},"page":"3-21","source":"Crossref","is-referenced-by-count":9,"title":["Exposing Security Risks for Commercial Mobile Devices"],"prefix":"10.1007","author":[{"given":"Zhaohui","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ryan","family":"Johnson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rahul","family":"Murmuria","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelos","family":"Stavrou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"2_CR1","doi-asserted-by":"crossref","unstructured":"Wang, Z., Stavrou, A.: Exploiting smart-phone usb connectivity for fun and profit. In: ACSAC 2010: Annual Computer Security Applications Conference (2010)","DOI":"10.1145\/1920261.1920314"},{"key":"2_CR2","doi-asserted-by":"crossref","unstructured":"Wang, Z., Murmuria, R., Stavrou, A.: Implementing & optimizing an encryption file system on android. In: SERE 2012: 6th International Conference on Software Security and Reliability, SERE 2012 (2012)","DOI":"10.1109\/MDM.2012.31"},{"key":"2_CR3","doi-asserted-by":"crossref","unstructured":"Wang, Z., Johnson, R., Stavrou, A.: Attestation & authentication for usb communications. In: IEEE International Conference on Mobile Data Management, IEEE MDM 2012 (2012)","DOI":"10.1109\/SERE-C.2012.43"},{"key":"2_CR4","first-page":"552","volume-title":"CCS 2008: Proceedings of the 15th ACM Conference on Computer and Communications Security","author":"W. Enck","year":"2008","unstructured":"Enck, W., McDaniel, P.: Understanding android\u2019s security framework. In: CCS 2008: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 552\u2013561. ACM, New York (2008)"},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Ongtang, M., Mclaughlin, S., Enck, W., Mcdaniel, P.: Semantically rich application-centric security in android. In: ACSAC 2009: Annual Computer Security Applications Conference (2009)","DOI":"10.1109\/ACSAC.2009.39"},{"key":"2_CR6","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1145\/1377836.1377862","volume-title":"SACMAT 2008: Proceedings of the 13th ACM Symposium on Access Control Models and Technologies","author":"D. Muthukumaran","year":"2008","unstructured":"Muthukumaran, D., Sawani, A., Schiffman, J., Jung, B.M., Jaeger, T.: Measuring integrity on mobile phone systems. In: SACMAT 2008: Proceedings of the 13th ACM Symposium on Access Control Models and Technologies, pp. 155\u2013164. ACM, New York (2008)"},{"key":"2_CR7","first-page":"255","volume-title":"OSDI 2010: Proceedings of the 9th Symposium on Operating Systems Design and Implementation","author":"W. Enck","year":"2010","unstructured":"Enck, W., Gilbert, P., gon Chun, B., Jung, L.P.C.J., McDaniel, P., Sheth, A.N.: Taintdroid: An information-flow tracking system for realtime privacy monitoring on smartphones. In: OSDI 2010: Proceedings of the 9th Symposium on Operating Systems Design and Implementation, pp. 255\u2013270. ACM, New York (2010)"},{"key":"2_CR8","doi-asserted-by":"crossref","unstructured":"Felt, A.P., Chin, E., Hanna, S., Song, D., Wagner, D.: Android permissions demystified. In: Chen, Y., Danezis, G., Shmatikov, V. (eds.) ACM Conference on Computer and Communications Security, pp. 627\u2013638. ACM (2011)","DOI":"10.1145\/2046707.2046779"},{"key":"2_CR9","doi-asserted-by":"crossref","unstructured":"Radmilo Racic, D.M., Chen, H.: Exploiting mms vulnerabilities to stealthily exhaust mobile phone\u2019s battery. In: SecureComm 2006, pp. 1\u201310 (2006)","DOI":"10.1109\/SECCOMW.2006.359550"},{"key":"2_CR10","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1145\/1378600.1378627","volume-title":"MobiSys 2008: Proceeding of the 6th International Conference on Mobile Systems, Applications, and Services","author":"H. Kim","year":"2008","unstructured":"Kim, H., Smith, J., Shin, K.G.: Detecting energy-greedy anomalies and mobile malware variants. In: MobiSys 2008: Proceeding of the 6th International Conference on Mobile Systems, Applications, and Services, pp. 239\u2013252. ACM, New York (2008)"},{"key":"2_CR11","first-page":"1","volume-title":"HICSS 2010: Proceedings of the 2010 43rd Hawaii International Conference on System Sciences","author":"B.R. Moyers","year":"2010","unstructured":"Moyers, B.R., Dunning, J.P., Marchany, R.C., Tront, J.G.: Effects of wi-fi and bluetooth battery exhaustion attacks on mobile devices. In: HICSS 2010: Proceedings of the 2010 43rd Hawaii International Conference on System Sciences, pp. 1\u20139. IEEE Computer Society, Washington, DC (2010)"},{"key":"2_CR12","first-page":"244","volume-title":"RAID 2009: Proceedings of the 12th International Symposium on Recent Advances in Intrusion Detection","author":"L. Liu","year":"2009","unstructured":"Liu, L., Yan, G., Zhang, X., Chen, S.: Virusmeter: Preventing your cellphone from spies. In: RAID 2009: Proceedings of the 12th International Symposium on Recent Advances in Intrusion Detection, pp. 244\u2013264. Springer, Heidelberg (2009)"},{"key":"2_CR13","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/PERCOMW.2005.86","volume-title":"PERCOMW 2005: Proceedings of the Third IEEE International Conference on Pervasive Computing and Communications Workshops","author":"D.C. Nash","year":"2005","unstructured":"Nash, D.C., Martin, T.L., Ha, D.S., Hsiao, M.S.: Towards an intrusion detection system for battery exhaustion attacks on mobile computing devices. In: PERCOMW 2005: Proceedings of the Third IEEE International Conference on Pervasive Computing and Communications Workshops, pp. 141\u2013145. IEEE Computer Society, Washington, DC (2005)"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Jiang, X.: Dissecting android malware: Characterization and evolution. In: IEEE Symposium on Security and Privacy, pp. 95\u2013109. IEEE Computer Society (2012)","DOI":"10.1109\/SP.2012.16"},{"key":"2_CR15","unstructured":"Zhou, Y., Wang, Z., Zhou, W., Jiang, X.: Hey, you, get off of my market: Detecting malicious apps in official and alternative android markets. In: Proceedings of the 19th Annual Network and Distributed System Security Symposium, NDSS (February 2012)"},{"key":"2_CR16","first-page":"296","volume-title":"SP 2008: Proceedings of the 2008 IEEE Symposium on Security and Privacy","author":"F.M. David","year":"2008","unstructured":"David, F.M., Chan, E.M., Carlyle, J.C., Campbell, R.H.: Cloaker: Hardware supported rootkit concealment. In: SP 2008: Proceedings of the 2008 IEEE Symposium on Security and Privacy, pp. 296\u2013310. IEEE Computer Society, Washington, DC (2008)"},{"key":"2_CR17","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1145\/1734583.1734596","volume-title":"HotMobile 2010: Proceedings of the Eleventh Workshop on Mobile Computing Systems & Applications","author":"J. Bickford","year":"2010","unstructured":"Bickford, J., O\u2019Hare, R., Baliga, A., Ganapathy, V., Iftode, L.: Rootkits on smart phones: attacks, implications and opportunities. In: HotMobile 2010: Proceedings of the Eleventh Workshop on Mobile Computing Systems & Applications, pp. 49\u201354. ACM, New York (2010)"},{"key":"2_CR18","unstructured":"Phrack: Hacking windows ce, \n                    \n                      http:\/\/www.phrack.org\/issues.html?issue=63&id=6"},{"key":"2_CR19","unstructured":"Bojinov, H., Boneh, D., Cannings, T.R., Malchev, I.: Address space randomization for mobile devices. In: Fourth ACM Conference on Wireless Network Security (WISEC 2011), pp. 127\u2013138 (2011), \n                    \n                      http:\/\/www.odysci.com\/article\/1010113016076341"},{"issue":"7","key":"2_CR20","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1145\/360248.360252","volume":"19","author":"J.C. King","year":"1976","unstructured":"King, J.C.: Symbolic execution and program testing. Commun. ACM\u00a019(7), 385\u2013394 (1976)","journal-title":"Commun. ACM"},{"key":"2_CR21","unstructured":"Enck, W., Octeau, D., McDaniel, P., Chaudhuri, S.: A Study of Android Application Security. In: Proceedings of the 20th USENIX Security Symposium (August 2011)"},{"key":"2_CR22","unstructured":"Vidas, T., Christin, N., Cranor, L.: Curbing Android permission creep. In: Proceedings of the Web 2.0 Security and Privacy 2011 Workshop (W2SP 2011), Oakland, CA (May 2011)"},{"key":"2_CR23","doi-asserted-by":"crossref","unstructured":"Bl\u00e4sing, T., Batyuk, L., Schmidt, A.D., Camtepe, S., Albayrak, S.: An android application sandbox system for suspicious software detection. In: 2010 5th International Conference on Malicious and Unwanted Software (MALWARE), pp. 55\u201362 (October 2010)","DOI":"10.1109\/MALWARE.2010.5665792"},{"key":"2_CR24","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/2046614.2046619","volume-title":"Proceedings of the 1st ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, SPSM 2011","author":"I. Burguera","year":"2011","unstructured":"Burguera, I., Zurutuza, U., Nadjm-Tehrani, S.: Crowdroid: behavior-based malware detection system for android. In: Proceedings of the 1st ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, SPSM 2011, pp. 15\u201326. ACM, New York (2011)"},{"key":"2_CR25","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1109\/ACSC.2001.906638","volume-title":"Proceedings of the 24th Australasian Conference on Computer Science, ACSC 2001","author":"M. Richmond","year":"2001","unstructured":"Richmond, M., Noble, J.: Reflections on remote reflection. In: Proceedings of the 24th Australasian Conference on Computer Science, ACSC 2001, pp. 163\u2013170. IEEE Computer Society, Washington, DC (2001)"},{"key":"2_CR26","unstructured":"Linux: Rsa kernel patch, \n                    \n                      http:\/\/lwn.net\/Articles\/228892\/"},{"key":"2_CR27","unstructured":"Community, L.O.S.: Linux usb authorization, \n                    \n                      http:\/\/lxr.linux.no\/linux+v2.6.32.24\/Documentation\/usb\/authorization.txt"},{"key":"2_CR28","first-page":"203","volume":"46","author":"D. Boneh","year":"1999","unstructured":"Boneh, D., Cryptosystem, T.R., Rivest, I.R., Shamir, A., Adleman, L., Rst, W.: Twenty years of attacks on the rsa cryptosystem. Notices of the AMS\u00a046, 203\u2013213 (1999)","journal-title":"Notices of the AMS"},{"key":"2_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1007\/BFb0053428","volume-title":"Advances in Cryptology - EUROCRYPT \u201994","author":"M. Bellare","year":"1995","unstructured":"Bellare, M., Rogaway, P.: Optimal Asymmetric Encryption. In: De Santis, A. (ed.) EUROCRYPT 1994. LNCS, vol.\u00a0950, pp. 92\u2013111. Springer, Heidelberg (1995)"},{"key":"2_CR30","unstructured":"Team, G.A.: Android honeycomb encryption, \n                    \n                      http:\/\/source.android.com\/tech\/encryption\/android_crypto_implementation.html"},{"key":"2_CR31","unstructured":"Whispercore: Whispercore android device encryption, \n                    \n                      http:\/\/whispersys.com\/whispercore.html"},{"key":"2_CR32","unstructured":"Project, O.: Openssl fips 140-2 security policy"},{"key":"2_CR33","unstructured":"Boost: Boost c++ library, \n                    \n                      http:\/\/www.boost.org\/"},{"key":"2_CR34","unstructured":"Librlog: Librlog, \n                    \n                      http:\/\/www.arg0.net\/rlog"},{"key":"2_CR35","unstructured":"Sharif, M.I., Lanzi, A., Giffin, J.T., Lee, W.: Impeding malware analysis using conditional code obfuscation. In: NDSS, The Internet Society (2008)"},{"issue":"6","key":"2_CR36","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MSP.2004.111","volume":"2","author":"B. Chess","year":"2004","unstructured":"Chess, B., McGraw, G.: Static analysis for security. IEEE Security and Privacy\u00a02(6), 76\u201379 (2004)","journal-title":"IEEE Security and Privacy"},{"key":"2_CR37","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Limits of static analysis for malware detection. In: Computer Security Applications Conference, ACSAC, Twenty-Third Annual, 421\u2013430 (December 2007)","DOI":"10.1109\/ACSAC.2007.4413008"},{"key":"2_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/978-3-540-74320-0_12","volume-title":"Recent Advances in Intrusion Detection","author":"J. Wilhelm","year":"2007","unstructured":"Wilhelm, J., Chiueh, T.-c.: A Forced Sampled Execution Approach to Kernel Rootkit Identification. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol.\u00a04637, pp. 219\u2013235. Springer, Heidelberg (2007)"},{"key":"2_CR39","doi-asserted-by":"crossref","unstructured":"Lu, S., Zhou, P., Liu, W., Zhou, Y., Torrellas, J.: Pathexpander: Architectural support for increasing the path coverage of dynamic bug detection. In: Proceedings of the 39th Annual IEEE\/ACM International Symposium on Microarchitecture, MICRO (2006)","DOI":"10.1109\/MICRO.2006.40"},{"key":"2_CR40","unstructured":"Brumley, D., Hartwig, C., Liang, Z., Newsome, J., Song, D., Yin, H.: Automatically Identifying Trigger-based Behavior in Malware. In: Botnet Analysis. Springer Publications (2007)"},{"key":"2_CR41","first-page":"231","volume-title":"SP 2007: Proceedings of the 2007 IEEE Symposium on Security and Privacy","author":"A. Moser","year":"2007","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Exploring multiple execution paths for malware analysis. In: SP 2007: Proceedings of the 2007 IEEE Symposium on Security and Privacy, pp. 231\u2013245. IEEE Computer Society, Washington, DC (2007)"}],"container-title":["Lecture Notes in Computer Science","Computer Network Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-33704-8_2.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,4]],"date-time":"2021-05-04T12:19:28Z","timestamp":1620130768000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-33704-8_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642337031","9783642337048"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-33704-8_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2012]]}}}