Android has become an active area of research owing to its vast range of applications called apps. Traditional security protocols which are complex are not feasible for such systems due to the limitation of resources. However, Elliptic Curve Cryptography has been considered as a viable cryptographic technique due to its low computational overhead. In this paper we study the application of ECC on a popular Android operating system. Practical implementation of the ECC operations has been performed using Android library. Android operating system has been used to develop custom security protocols on a Smartphone. The performance benchmarking of the proposed protocols has also been carried out.
Background/Objectives: The widely spread Smartphone operating systems i.e. iOS and Android are loaded with the inherent security measures to protect their millions of users worldwide. Android, being familiar and popular in open supply mobile package i.e. open source platform has some security limitations or vulnerabilities which are also present in iOS that is owned by Apple and is a proprietary platform with some open supply parts. Methods/Statistical Analysis: We compare the basic protection options of Android and iOS, with the objective to combine the user approved security (UAS) model in Android so that we are able to grant permissions to access various resources on a Smartphone at the time of execution. Findings: In this paper we propose the implementation of a reverse engineering method that restricts Access of the resources and provides a requirement based procedure to access resources. Applications/Improvements: By incorporating the user approved security, the repackaged app would be more secure and will be capable of running on all the devices.
Smart phones have already become an important part of our lives. Smartphone is in the hands of millions of novice users who are unaware of the security concerns they may face. In order to address the security concerns of the millions of users, we propose and implement three novel techniques to enhance the security of these Smartphone’s. The first Technique is Need based Security (NBS) wherein we take away the flexibility from the programmer and give the control to the users who can decide whether to permit the application to access any of the resources or not. In our second Technique we used the security API which will take care of everything in background and in our third technique we locked all the applications so that they can be restricted from doing any malicious activity. We tried to find out the security loopholes in one of the leading Smartphone operating system i.e. Android with the intension to apply the novel techniques proposed and implemented in this paper.
Cryptographically generated address (CGA) is a prime inherent element of SEND protocol introduced in IPv6.CGA works without relying on any trusted third party authority or Public Key Infrastructure (PKI).CGA find their application in proving address ownership and prevent spoofing or theft of IPv6 addresses by binding senders public key with the generated address. Though CGA is a promising technique and offers substantial amount of security, it does possess some limitations and performance bottlenecks. CGA is computationally intensive determined by the security parameter 'sec' and bandwidth gobbling due to use of RSA keys. For a higher value of 'sec', there is no guarantee on termination of brute force search for modifier. This paper evaluates the performance and discusses possible techniques that can be used in optimizing the use of IPv6 CGA. The techniques discussed are the possible modifications to the standard RFC 3972.These include reducing the granularity factor of sec from 16 to 8, replacing RSA with ECC and ECSDSA, using SHA-256 hash function instead of SHA-1 and including subnet prefix in the calculation of CGA. The paper also compares the modified CGA with standard CGA and advocates the reasons for incorporating these changes so that enhanced hybrid version of CGA can be obtained.
The Neighbor Discovery Protocol (NDP) is the predominant component in IPv6; the next generation internet protocol providing for stateless address auto configuration of nodes (SLAAC), resolution of link layer addresses and neighbor unreachability detection. The stateless address auto configuration is designed for self configuration of nodes and achieving plug and play support for network devices. The protocol is rooted on the assumption that network consists of trusted nodes, however with emergence of public wireless networks; any node can join the link with minimal authentication and the condition changes drastically. With no inclusion of central address configuration servers or trusted authorities, the process is vulnerable to malicious activities. The attacker can impersonate legitimate nodes and launch Man-in-the-Middle (MITM), Denial of Service (DoS), and other network related attacks. The access to the link can be blocked and the network traffic can be redirected without the knowledge of users. To overcome the above problem, RFC 3971 suggests the use of Cryptographically Generated Addresses (CGA) which is an innate component of Secure Neighbor Discovery (SEND). Although CGA provides for message integrity, authentication and mitigating address impersonation, the process is computation intensive with higher bandwidth consumption and harbors some other limitations. This paper presents a novel technique for address generation having a minimal computation cost as compared to CGA. The technique generates a highly randomized Interface Identifier that helps maintain nodes privacy and allows the nodes to ascertain the uniqueness on the link. It also provides robust security against DoS attacks during the DAD process of IPv6 SLAAC.
Smartphones have become an essential rather than an optional gadget. With Smartphones, we carry with us a hand held computer with details about our social life, family members, transaction details and much more. Smartphones serve as a communication tool used to send messages, place and receive calls, surf the internet and play wide range of games. In this paper, we present a framework that helps us to track and pin-point the current location of the mobile and save the call logs, sent to our Web-based application. This framework couples GPS-based information with Google maps data and accurately determines the postal address of the lost mobile. The framework makes it possible to track the mobile location after specified regular intervals.
IPSec is the amalgam of protocols dispensing security in IP networks. It has been the rudimentary security component in IPv4 and IPv6 networks providing for data authentication, integrity and confidentiality. Earlier security was not embedded at the IP level however with emergence of large scale public and corporate internets, the user data became vulnerable to malicious activities like privacy attacks and thefts. To mitigate this and secure network traffic, IETF introduced IPSec for robust network communications. IPSec is a framework that provides sublime options for encryption and authentication of data packets. IPSec architecture provides a flexible and agile approach for securing network traffic. Initially IPSec was introduced as an additional component in IPv4, but in next generation internet protocol IPv6, it's an inbuilt component implemented as a part of extension header. Although IPSec is the panacea for securing IP protocol, its implementation and management is unequivocally complex in nature. The implementation involves key management and exchange through IKE, protocol negotiations and establishment of security associations which can significantly decrease performance and degrade IP communication. This fact has a significant impact on real time communication. This paper makes an empirical investigation of the parameters that are affected by implementation of IPSec in IPv6 and 6to4 Tunneled Migration Networks. The investigation is significant and evaluates about the performance decay that is encountered by incorporating security. The simulation approach is used and measurements are performed in OPNET Simulator ver. 14.5.
Quality of Service (QoS) is an important network performance parameter having significant impact on real time applications like VoIP, Interactive gaming and Video Streaming. Although IPv6 was designed to improve addressing, security and QoS in IPv4, services like Video Conferencing and VoIP with strong reliance and sensitivity towards delay and jitter pose a daunting challenge in today's packet based networks. These parameters must be well below the level of tolerance so that the service doesn't degrade. In this paper we discuss various parameters and dimensions on which the QoS of network depends. We also discuss the mechanisms used by IPv4 and IPv6 to implement QoS. Finally performance analysis of different queuing algorithms like FIFO, WFQ and PQ is carried out to study their impact on real time applications in IPv6 Environment. A simulation framework based on OPNET Modeler 14.5 is used to model, simulate and analyze network behavior.
The increasing number of mobile operating systems that operate the small hand held devices collectively called Smartphones, have become an integral part of our lives. The openness of these new environments has lead to new domain of apps and markets and has enabled greater integration with existing online services like e-banking etc. Smartphone makers are competing in turns to outgun each other for storage, processor speed, platform compatibility and camera megapixels but it's the predominantly software - the mobile OS - that makes the biggest divergence to the popularity and market share of Smartphone. This paper evaluates the popular Smartphone Operating Systems with the purpose of understanding the user friendliness, popularity, user privacy, security and accessibility with respect to the wide domain of apps. This paper focuses on the advantages and limitations of the Smartphone operating systems with the intention to determine if one of them has an edge over the other and, finally, we propose broad enhancements aimed at making them more user-friendly and secure.
6in4 is the IPv4 to IPv6 migration technique that uses tunneling to encapsulate IPv6 packets over configured IPv4 communication links. This paper attempts to evaluate and compare performance parameters like Throughput, IP End-to-End Delay and Response Time of different applications running on the internet in IPv4, IPv6 and 6in4 manual tunneling environments. The applications that we are modeling are Database Application, Web Browsing, Video conferencing, Voice Communications and Remote Login. This paper aims to evaluate the performance of these internet applications in three different networks. The results of the study will be important for network administrators and various Internet Service Providers (ISP) for planning of IPv6 migration networks. OPNET Modeler ver. 14.5. has been used for simulation study. The networks that have been modeled consist of different components like client workstations, routers, servers and network backbones.
IP Next Generation (IPng) or IPv6 engineered by IETF is the successor of IPv4, the contemporary version of Internet Protocol. IPv6 is designed to solve the long term performance, reliability and scalability problems of IPv4. Although IPv6 implementation is yet to attain a maturity level, its success will ultimately depend on its implementation in a broader perspective. The IPv6 network migration is seen as an intricate daunting task impeding its evolution. Nevertheless with emergence of new IPv6 migration techniques, its complete integration with current IP networks seems to be achievable in near future. This paper attempts to examine current IP transitioning techniques and outlines the key deployment issues, challenges and migration paths. The paper also makes an empirical evaluation of three most commonly used transition mechanisms namely Dual S tack, Automatic 6to4 Tunneling and Manual 6in4 Tunneling and makes a comparison of performance metrics with native IPv6 environment. The simulation results are significant and give an insight about choosing best transition technique and an idea about network migration and capacity planning. The simulation-based comparison has been carried using OPNET (ver. 14.5) simulation framework.
Cloud computing has become a key component as well as a measure of success for various organizations today.Apart from benefits obtained, it is important to take into account the location of user-base and data-center, which is essential for performance and security reasons, since the location of datacenter and user-base can impact the overall response time.In this paper evaluation of the effect on overall response time, of relevant factors such as the location of data-center and the serviced user-base is done.
Cloud Computing is the latest technology considered now-a-days. Cloud Computing uses the concepts of metered service i.e. pay as you go, as per the requirement of the user. Cloud Computing includes the concept of grid computing, utility in computing, and of course storage in cloud. In this paper, we present the introduction of cloud computing and emphasize on the security aspects of cloud computing.
The most popular Smartphone platforms i.e. Android and iOS are equipped with the built-in security features to safeguard their end users. Android, being an Open Source Mobile Operating System, has some security vulnerabilities. Such limitations are also present in iOS which is a proprietary platform with some open source components. In this paper we will compare in detail the security features of Android and iOS, with the intent to integrate the need based security (NBS) model in Android which selectively grants permission to access resources on a Smartphone at run time. This paper proposes the implementation of a reverse engineering process which restricts an app's permissions and provides a need based mechanism to access resources. The repackaged app with need based security will run on all devices that were supported by the original application.
Cloud computing is a key component as well as a measure of success for various organizations today. Apart from benefits obtained, it is important to take into account the location of user-base and data-centre, which is essential for performance and security reasons. This information is required since the location of data-centre and user-base can impact the overall response time. In this paper we evaluate the effect on overall response time, of relevant factors such as the location of data-centre and the serviced user-base.
With the widespread use of the Smartphone, the security of data stored in a Smartphone has reached to an utmost importance to all of us.Installation of every Android app asks for some critical permission to access our critical files and we have to accept the permissions in order to install that application.We propose a novel approach of enhanced security framework which can be integrated with the existing Android Security Framework to make Android more secure and to keep track of the files accessed by any of the vulnerable apps downloaded from different sources on the web.The proposed enhanced security framework enhances the security of Android File System by restricting the apps whose behavior matches with the malware.A novel approach to secure the data on Smartphone's using cryptographic Algorithms is also discussed in this paper.
Currently, smart phones are becoming indispensable for meeting the social expectation ofalways staying connected and the need for an increase inproductivity are the reasons for the increase in smartphone usage. One of the leaders of the smart phone evolution is Google’s Android operating system. It ishighly likely that Android is going to be installed in manymillions of cell phones during the near future. With thepopularity of Android smart phones everyone finds it convenient to make transactions through these smartphones because of the openness of Android applications. The malware attacks are also significant. Androidsecurity is complex and we evaluate an applicationdevelopment environment which is susceptible tomalware attacks. This paper evaluates Android securitywith the purpose of identifying a secure applicationdevelopment environment for performing securetransactions on Android-based smart phones.
Mobile Ad hoc networks (MANETs) are collections of wireless mobile nodes dynamically reconfiguring and collectively forming a temporary network. These types of networks assume existence of no fixed infrastructure and are often useful in battle-field tactical operations or emergency search-and-rescue type of operations where fixed infrastructure is neither feasible nor practical. They also find use in ad hoc conferences, campus networks and commercial recreational applications carrying multimedia traffic. All of the above applications of MANETs require guaranteed levels of performance as experienced by the end-user. This paper focuses on key challenges in provisioning predetermined levels of such Quality of Service (QoS). It also identifies functional areas where QoS models are currently defined and used. Evolving functional areas where performance and QoS provisioning may be applied are also identified and some suggestions are provided for further research in this area. Although each of the above functional areas have been discussed separately in recent research studies, since these QoS functional areas are highly correlated and interdependent, a comprehensive and comparative analysis of these areas and their interrelationships is desired. In this paper we have attempted to provide such an overview. Keywords—Bandwidth Reservation, Congestion, Dynamic Network Topology, End-to-End Delay, Flexible QoS Model for MANET(FQMM), Hidden Terminal, Mobile Adhoc Network(MANET), Packet Jitter, Queuing, Quality-of-Service (QoS), Relative Bandwidth Service Differentiation(RBSD), Resource ReSerVation Protocol (RSVP).