Honey, I Shrunk Your App Security: The State of Android App Hardening [chapter]

Vincent Haupert, Dominik Maier, Nicolas Schneider, Julian Kirsch, Tilo Müller
2018 Lecture Notes in Computer Science  
The continued popularity of smartphones has led companies from all business sectors to use them for security-sensitive tasks like two-factor authentication. Android, however, suffers from a fragmented landscape of devices and versions, which leaves many devices unpatched by their manufacturers. This security gap has created a vital market of commercial solutions for Runtime Application Self-Protection (RASP) to harden apps and ensure their integrity even on compromised devices. In this paper,
more » ... assess the RASP market for Android by providing an overview of the available products and their features. Furthermore, we describe an in-depth case study for a leading RASP product-namely Promon Shield -which is being used by approximately 100 companies to protect over 100 million end users worldwide. We demonstrate two attacks against Promon Shield: The first removes the entire protection scheme statically from an app, while the second disables all security measures dynamically at runtime.
doi:10.1007/978-3-319-93411-2_4 fatcat:j5sygtkqfbechhgnca4b64ii5u