2012年12月17日星期一

Abandon android or abandon security?

Since become mainstream smartphone android system mobile phone security issues have been can not be ignored, however, limited by the mechanism of the android platform itself, the security issue has been unable to be properly addressed. Even moviles baratos also have the right to safety.
Application validation is a feature of the new development of Google new Android 4.2 application authentication features download software can detect whether they carry the virus. This feature seems to be a good application, but the function is tested, the function does not think so powerful, it can only detect about 20% of the malicious software. Of course, from the current understanding of the situation, found that only about 0.5% of the protection software from Google Play Store, Google is also doing this work. However, there are still 95.5% of malware is coming from other sources, especially like some Play Store is not used.
The test is done by the North Carolina State University, Department of Computer Science Professor Xuxian Jiang, his run Android 4.2 Nexus 10 phones for testing, testing out the 1260 models of malicious software. Found that the scanning function can only be detected by the system comes out of the 193 models, the recognition rate was only 15.32%. Professor at random from each of malicious software in extracting a sample of ten representative of the anti-virus software on the test, including Kaspersky Kingsoft. Found that antivirus software malware recognition rate of 51% to 100%, while Google's own scan function is only 20%.
Professor Jiang that Google detects malware recognition rate is mainly due to two reasons. First, the application is the use of cryptographic hash signatures to the screening software is not malware, but hash signature is very easy to be tampered with and neglect. Second, the application is based networking cloud computing, has not set the offline scan feature, which means that if your phone is not the Internet, it will not be able to detect malicious software.
In fact, Google should program control is returned to the user, allowing users to give the software appropriate permissions. This can be good to circumvent the problems caused by malicious software on the user.We do not want Google to provide security services like the adornos navidad, can only look, can not be used.

没有评论:

发表评论