An Investigation of the Android Kernel Patch Ecosystem
Zheng Zhang, Hang Zhang, Zhiyun Qian, Billy Lau
摘要
open-source projects are often reused in commercial software. Android, a popular mobile operating system, is a great example that has fostered an ecosystem of open-source kernels. However, due to the largely decentralized and fragmented nature, patch propagation from the upstream through multiple layers to end devices can be severely delayed. In this paper, we undertake a thorough investigation of the patch propagation behaviors in the entire Android kernel ecosystem. By analyzing the CVEs and patches available since the inception of the Android security bulletin, as well as open-source upstream kernels (e.g., Linux and AOSP) and hundreds of mostly binary OEM kernels (e.g., by Samsung), we find that the delays of patches are largely due to the current patching practices and the lack of knowledge about which upstream commits being security-critical. Unfortunately, we find that the gap between the first publicly available patch and its final application on end devices is often months and even years, leaving a large attack window for experienced hackers to exploit the unpatched vulnerabilities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper26
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu 等ICSE 2022 · 被引用 21 次
- Understanding the Practice of Security Patch Management across Multiple Branches in OSS ProjectsXin Tan, Yuan Zhang, Jiajun Cao, Kun Sun 等WWW 2022 · 被引用 19 次
- SyzGen++: Dependency Inference for Augmenting Kernel Driver FuzzingWeiteng Chen, Yu Hao, Zheng Zhang, Xiaochen Zou 等S&P 2024 · 被引用 12 次
- Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoTXin'an Zhou, Jiale Guan, Luyi Xing, Zhiyun QianCCS 2022 · 被引用 9 次
- Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android KernelsLukas Maar, Florian Draschbacher, Lukas Lamster, Stefan MangardUSENIX Security 2024 · 被引用 5 次
它引用的顶会 Paper4
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin 等CCS 2017 · 被引用 682 次
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Precise and Accurate Patch Presence Test for BinariesHang Zhang, Zhiyun QianUSENIX Security 2018 · 被引用 91 次
- Precisely Characterizing Security Impact in a Flood of Patches via Symbolic Rule ComparisonQiushi Wu, Yang He, Stephen McCamant, Kangjie LuNDSS 2020
相关 Paper
- 50 Shades of Support: A Device-Centric Analysis of Android Security UpdatesAbbas Acar, Güliz Seray Tuncay, Esteban Luques, Harun Oz 等NDSS 2024
- Deploying Android Security Updates: an Extensive Study Involving Manufacturers, Carriers, and End UsersKailani R. Jones, Ting-Fang Yen, Sathya Chandran Sundaramurthy, Alexandru G. BardasCCS 2020 · 被引用 14 次
- Adaptive Android Kernel Live PatchingYue Chen, Yulong Zhang, Zhi Wang, Liangzhao Xia 等USENIX Security 2017 · 被引用 60 次
- The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel VulnerabilitiesLukas Maar, Florian Draschbacher, Lorenz Schumm, Ernesto Martínez García 等USENIX Security 2025
- Vulnerability, Where Art Thou? An Investigation of Vulnerability Management in Android Smartphone ChipsetsDaniel Klischies, Philipp Mackensen, Veelasha MoonsamyNDSS 2025
