Lightweight Mobile Applications Certification: Prepared By: Rahul Biswas.

Post on 26-Dec-2015

216 Views

Category:

Documents

0 Downloads

Preview:

Click to see full reader

Transcript

Lightweight Mobile Applications Certification:

Prepared By: Rahul Biswas

Metamorphosis: Today Old Times

Mobile Applications:Mobile phones or so calledSmartphones have becometechnologically very advanced.

Users are downloading/installing increased number of applicationsvia online application stores.

Threat Perception:Increased number of downloads= increased threat of getting a malware installed.

Not all the Applications have been thoroughly tested or went through due diligence.

Solution:Performing * Lightweight certification of Applications* while installing.

Most effective phone malware mitigationstrategy till now is to ensure “that only approved software can be installed”

Kirin Certification:Kirin security service for Android phones

Kirin certification basically uses security rules.

Security rules are basically templates which are designed to match unwanted properties in the security configuration.

Kirin Certification:The focus of Kirin is on Google-led Android platform, because it: Combines useful security information with applications 

Is already adopted by major American and EU service

providers Is open source.

Kirin Security service:Design of Kirin is such that it serves as a

security service which is running on the smartphone.

Interface of the installer directly interacts with the Security service. 

Kirin Certification:1. Practicality factor.

2.Prevent malware and allow legitimate software.

The Road ahead:

The best defense mechanism for mobile phone malware is still not clear .

Operating systems own protection and security mechanisms have been improving. e,g. Technical flaw for Cabir fixed.

Anti-virus software also act as a second layer of defense against malware.

Conclusion:Technology like Kirin provides Lightweight

Mobile application certification at the install time and thus helps a lot in installing only the legitimate application on the smartphone.

 

Thank You

top related