Assessing the Feasibility of the Virtual Smartphone Paradigm in Countering Zero-Click Attacks

dc.contributor.authorShafqat, Narmeen
dc.contributor.authorTopcuoglu, Cem
dc.contributor.authorKirda, Engin
dc.contributor.authorRanganathan, Aanjhan
dc.date.accessioned2023-12-26T18:53:59Z
dc.date.available2023-12-26T18:53:59Z
dc.date.issued2024-01-03
dc.identifier.doi10.24251/HICSS.2024.892
dc.identifier.isbn978-0-9981331-7-1
dc.identifier.otherbbcbf17c-64cd-4657-8655-761e53f62c46
dc.identifier.urihttps://hdl.handle.net/10125/107278
dc.language.isoeng
dc.relation.ispartofProceedings of the 57th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCybersecurity and Software Assurance
dc.subjectmobile security
dc.subjectpegasus spyware
dc.subjectvirtual smartphone.
dc.subjectzero-click attacks
dc.subjectzero-day
dc.titleAssessing the Feasibility of the Virtual Smartphone Paradigm in Countering Zero-Click Attacks
dc.typeConference Paper
dc.type.dcmiText
dcterms.abstractZero-click attacks exploit unpatched vulnerabilities in chat apps, such as WhatsApp and iMessage, enabling root access to the user's device without their interaction, thereby posing a significant privacy risk. While Apple's Lockdown mode and Samsung's Message Guard implement virtual sandboxes, it is crucial to recognize that sophisticated zero-click exploits can potentially bypass the sandbox and compromise the device. This paper explores the feasibility of countering such attacks by shifting the attack surface to a virtual smartphone ecosystem, developed using readily available off-the-shelf components. Considering that zero-click attacks are inevitable, our cross-platform security system is strategically designed to substantially reduce the impact and duration of any potential successful attack. Our evaluation highlighted several trade-offs between security and usability. Moreover, we share insights to inspire further research on mitigating zero-click attacks on smartphones.
dcterms.extent10 pages
prism.startingpage7427

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0725.pdf
Size:
709.4 KB
Format:
Adobe Portable Document Format