140 likes | 321 Views
Lightweight Mobile Applications Certification:. Prepared By: Rahul Biswas. Old Times. Metamorphosis:. Today. Mobile Applications:. Mobile phones or so called Smartphones have become technologically very advanced .
E N D
Lightweight Mobile Applications Certification: Prepared By: Rahul Biswas
Old Times Metamorphosis: Today
Mobile Applications: Mobile phones or so called Smartphoneshave become technologically very advanced. Users are downloading/installing increasednumber of applications via online application stores.
Threat Perception: • Increased number of downloads = increased threat of getting a malware installed. • Not all the Applications have been thoroughly tested or went through due diligence.
Solution: Performing * Lightweight certification of Applications* while installing. Most effective phone malware mitigation strategy till now is to ensure “that only approved software can be installed”
Kirin Certification: • Kirin security service for Android phones • Kirin certification basically uses security rules. • Security rules are basically templates which are designed to match unwanted properties in the security configuration.
Kirin Certification: The focus of Kirin is on Google-led Android platform, because it: • Combines useful security information with applications • Is already adopted by major American and EU service providers • Is open source.
Kirin Security service: • Design of Kirin is such that it serves as a security service which is running on the smartphone. • Interface of the installer directly interacts with the Security service.
Kirin Certification: 1. Practicality factor. 2.Prevent malware and allow legitimate software.
The Road ahead: • The best defense mechanism for mobile phone malware is still not clear . • Operating systems own protection and security mechanisms have been improving. e,g. Technical flaw for Cabir fixed. • Anti-virus software also act as a second layer of defense against malware.
Conclusion: • Technology like Kirin provides Lightweight Mobile application certification at the install time and thus helps a lot in installing only the legitimate application on the smartphone.