Yossi Oren

Senior Academic

From smashed screens to smashed stacks

Attacking mobile phones using malicious aftermarket parts

Omer Shwartz, Guy Shitrit, Asaf Shabtai,Yossi Oren

In this preliminary study we present thefirst practical attack on a modern smartphone whichis mounted through a malicious aftermarket replace-ment part (specifically, a replacement touchscreen). Our attack exploits the lax security checks on thepackets traveling between the touchscreen's embed-ded controller and the phone's main CPU, and isable to achieve kernel-level code execution privilegeson modern Android phones protected by SELinux. This attack is memory independent and survives datawipes and factory resets. We evaluate two phonesfrom major vendors and present a proof-of-concept attack in actual hardware on one phone and an emulation level attack on the other. Through a semi-automated source code review of 26 recent Androidphones from 8 different vendors, we believe that ourattack vector can be applied to many other phones, and that it is very difficult to protect against. Similarattacks should also be possible on other smart devicessuch as printers, cameras and cars, which similarlycontain user-replaceable sub-units.

Publication language English
Pages 94-98
Publication status Published - 30.06.2017
7966977

Keywords

Android
Cyber security
Driver
Hardware security
Smarthphone

ASJC Scopus subject areas

Computer Networks and Communications
Safety, Risk, Reliability and Quality
Access to Document
10.1109/EuroSPW.2017.57
Other files and links
Link to publication in Scopus