2017Android安全回顾(英文)_56页-2mb
报告摘要
Android Security 2017 Year In Review Summary
Core Content
This report provides an overview of Android security improvements in 2017, highlighting the effectiveness of Google's security measures, the role of the open-source model, and the expansion of enterprise security features. It also details the evolution of Google Play Protect, the enhancement of platform-level security, and the impact of architectural changes like Project Treble.
Main Points
- Android Security Improvements: Android security made significant progress in 2017, with notable reductions in PHAs (Potentially Harmful Applications) and enhanced protection mechanisms.
- Google Play Protect: This service is the most widely deployed mobile threat protection in the world, with over 2 billion devices running Android 4.3+ and Google Play.
- Open Source Strength: Android's open-source model allows for a larger and more effective community of defenders, making it harder for attackers to exploit the platform.
- Enterprise Security: Android's enterprise features, such as work profiles and managed Google Play, increased in adoption and functionality.
- Technical Enhancements: New features and improvements were introduced to enhance security, including machine learning capabilities, offline PHA scanning, and the re-architecture of Verified Boot.
Key Information
Google Play Protect
- Overview: Google Play Protect is a built-in security feature that scans devices for PHAs and provides users with control and visibility over their device's security.
- Features:
- Daily PHA Scan: Launched in 2016, daily scans helped identify and remove approximately 39 million PHAs in 2017.
- On-demand Scan: Users can initiate full scans at any time.
- Offline Scan: Added in October 2017, this feature blocked over 10 million harmful app installs.
- Automatic Disabling: PHAs can be automatically disabled without uninstalling, reducing user inconvenience.
- Review Apps from Outside Google Play: Google reviews apps from various sources to ensure they are not harmful, and users can enable the "Improve harmful app detection" feature to allow this.
Platform Security
- Security Features:
- Encryption: Protects data from unauthorized access.
- Hardware-backed Security: Enhances key storage and enables strong remote authentication.
- Kernel Self-protections: Prevents memory corruption and other kernel vulnerabilities.
- Sandboxing: Isolates apps to protect data and processing.
- SELinux: Enforces security boundaries across the OS and apps.
- Userspace Hardening: Includes ASLR and DEP to prevent memory corruption.
- Verified Boot: Ensures the OS starts in a known good state and prevents unauthorized modifications.
Android 8.0 (Oreo) and Project Treble
- Project Treble:
- A major architectural change that simplifies the update process for Android devices.
- Separates the Android framework from the vendor implementation, improving modularity and security.
- Allows for faster and more efficient security updates.
- Verified Boot 2.0 (AVB):
- Works with Project Treble to improve security.
- Uses separate signing keys for individual partitions, enabling more flexible updates.
- Implements rollback protection to prevent the use of old, vulnerable images.
Enterprise Growth
- Work Profile:
- Separates business and personal data, enhancing privacy and security.
- Validated with nearly 40 EMM (Enterprise Mobility Management) providers.
- Managed Google Play:
- A curated store for enterprise users.
- The number of 30-day active devices increased by 2000% in 2017.
- Verify Apps API:
- Helps administrators determine device security status and manage PHAs.
Security Metrics
- PHA Reduction: The annual probability of downloading a PHA from Google Play dropped from 0.04% in 2016 to 0.02% in 2017.
- Security Patch Increase: Over 30% more devices received security patches in 2017 compared to 2016.
- Machine Learning: Detected 60.3% of PHAs in 2017, improving threat classification and response.
Safe Browsing
- Overview: Introduced in 2007, Safe Browsing protects users from phishing and PHA host sites.
- Android 8.0: Made Safe Browsing an opt-in feature, enhancing user control and security.
- Impact: Safe Browsing protects over 3 billion devices and shows over a million warnings a month.
Third-party Analysis
- Vulnerability Rewards Program: Demonstrated increased difficulty in exploiting Android, with higher exploit pricing.
- Mobile Pwn2Own: No core Android platform security exploits were rewarded in 2017, showing improved platform security.
Conclusion
2017 marked a significant year for Android security, with substantial improvements in PHA detection, user protection, and platform-level security. Google's collaboration with partners, the use of machine learning, and the architectural changes introduced in Android 8.0 all contributed to making Android a more secure platform. The open-source nature of Android and the growing ecosystem of security-focused partners further strengthened its defenses.
试读结束,高清完整版pdf/doc/ppt,请点下载