The United States National Security Agency (NSA) has released a security-hardened version of Android, designed to cut down the litany of security risks affecting the mobile operating system.
The Security Enhanced (SE) Android system is based on the NSA-developed SELinux feature.
It was first flagged by the spy agency last year as a means to prevent damage from malicious or vulnerable applicatons.
"Initially, the SEAndroid project is enabling the use of SELinux in Android in order to limit the damage that can be done by flawed or malicious apps and in order to enforce separation guarantees between apps," the NSA said on its website for the project.
Specifically, SEAndroid can: confine and protect privileged daemons; sandbox and accurately isolate applications and prevent privilege escalation; and introduce a centralised policy.
It generally cannot prevent Kernel vulnerabilities but can, in some instances, prevent exploitation.
At the Linux Security Conference last year, NSA developer Stephen Smalley demonstrated how SEAndroid would defeat a string of previously successful Android root exploits including GingerBreak, RageAgainstTheCage, and ueventd.
The NSA released SEAndroid source code for the first time earlier this month.
According to the project website, new features in the the hardened SEAndroid platform include:
Copyright © SC Magazine, Australia
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED GOES EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @itnews.com.au to your white-listed senders.