发明名称 DETECTION OF PILEUP VULNERABILITIES IN MOBILE OPERATING SYSTEMS
摘要 A system is provided for detecting pileup vulnerabilities corresponding to mobile operating system updates. The system includes: an exploit opportunity analyzer, configured to identify pileup exploit opportunities corresponding to a plurality of mobile operating system configurations based on mobile operating system upgrades for each of the plurality of mobile operating system configurations, wherein the identification of exploit opportunities is based on information relating to pileup flaws; a risk database, configured to store information regarding the identified pileup exploit opportunities for a plurality of versions of each of the plurality of mobile operating system configurations; and a scanner application, configured to be executed by a mobile device, configured to query identified exploit opportunities relating to a particular mobile operating system configuration and version, and to evaluate third-party applications installed at the mobile device based on the identified exploit opportunities.
申请公布号 US2016044049(A1) 申请公布日期 2016.02.11
申请号 US201414456719 申请日期 2014.08.11
申请人 Indiana University Research and Technology Corporation 发明人 XING Luyi;WANG XiaoFeng
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A system for detecting pileup vulnerabilities corresponding to mobile operating system updates, the system comprising: an exploit opportunity analyzer, configured to identify pileup exploit opportunities corresponding to a plurality of mobile operating system configurations based on mobile operating system upgrades for each of the plurality of mobile operating system configurations, wherein the identification of exploit opportunities is based on information relating to pileup flaws; a risk database, configured to store information regarding the identified pileup exploit opportunities for a plurality of versions of each of the plurality of mobile operating system configurations; and a scanner application, configured to be executed by a mobile device, configured to query identified exploit opportunities relating to a particular mobile operating system configuration and version, and to evaluate third-party applications installed at the mobile device based on the identified exploit opportunities.
地址 Indianapolis IN US