Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Android
    • Android
    • Cybersecurity
    • Mobile
    • Servers

    NSA Releases SE Android With Better Sandboxing, Access-Control Policies

    Written by

    Fahmida Y. Rashid
    Published January 19, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The National Security Agency has publicly released SE Android, a secure version of Google’s mobile operating system.

      A security-enhanced version of Android, SE Android would enforce stricter access-control policies and better sandboxing than what is currently available in the most up-to-date version of Google Android. The NSA announced the project at the Linux Security Summit in September and released the first version Jan. 6.

      SE Android is based on SE Linux, a hardened version of Linux that the NSA initially released in 2000. Several SE Linux components have eventually made it back into the official Linux kernel as well as various Linux distributions, Solaris and FreeBSD.

      “Security Enhanced (SE) Android is a project to identify and address critical gaps in the security of Android,” the agency wrote in the project documentation.

      As designed, SE Android would isolate applications from each other, mitigate problems introduced by flawed or malicious applications, prevent applications from accessing system resources, ensure proper permission levels and perform security checks. Every file and folder on the device can be individually locked and encrypted, and WiFi and mobile network security features have been enhanced.

      Android’s application security model allows applications run by a particular user to have access to all the files and resources normally available to that user. This has been an issue with applications having too much control over device elements like Bluetooth and the camera. SE Android uses Mandatory Access Control, which relies on policies to restrict the system resources available to the application regardless of user permissions.

      “Even if an application were to break out its security sandbox, it would have limited ability to affect core system functionality,” Cameron Camp, an ESET researcher, wrote on the ESET Threat Blog.

      The team is expected to further incorporate SE Android into Application Layer Security, to thwart unauthorized access and compromised programs at the application layer instead of letting it reach the kernel.

      The NSA does not appear to be offering SE Android as the answer to all kernel issues, according to a presentation from the Linux Security Summit, but it suggested that many existing exploits would have been stopped with SE Android. Published Android root exploits, such as GingerBreak, Exploid or RageAgainstTheCage, target vulnerabilities in Android services and launch processes. SE Android can block the GingerBreak exploit at six different steps during its execution, depending on how strict the enforced policies are, NSA’s Stephen Smalley said in the presentation.

      NSA is clearly targeting mobile developers, security experts and device manufacturers who need to implement strict access-control policies, such as the ones mandated by the U.S. Department of Defense, in mobile devices and applications.

      While it remains to be seen if SE Android will see widespread commercial adoption, it seems to indicate a growing role for Android in enterprise settings where SE platforms are currently deployed, according to Camp. “Having more security options for the mobile platform seems like a move in a positive direction,” Camp said.

      Installing SE Android-still in its early stages-is a fairly complex process as there are no precompiled binaries available. Interested users and developers would need to download and build the official Android Open Source Project source code before obtaining patches and modifications from the SE Android code repositories. However, some developers are already discussing plans to release packaged versions to make it easier to work with.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.