RILDEFENDER: System-level defense from SMS attacks in Android smartphones
T2024-407
The Need
Mobile devices remain vulnerable to SMS-based attacks, which can bypass app-layer defenses and exploit low-level system components. Existing solutions are either passive, OS-specific, or require extensive hardware modifications, leaving a critical gap in real-time, system-level protection. There is a pressing need for a broadly applicable, inline defense mechanism that can detect and mitigate SMS threats at the foundational communication layer of smartphones.
The Technology
RILDEFENDER is the first inline, system-level SMS defense integrated into the Radio Interface Layer (RIL) of Android smartphones. Unlike app-layer or hardware-dependent solutions, RILDEFENDER operates at the OS baseband interface, enabling real-time detection and mitigation of malicious SMS messages. Implemented as an AOSP extension, it introduces a policy-driven security framework that mediates all SMS traffic between the baseband, SIM, and Android kernel, offering proactive protection across diverse devices and threat models.
Commercial Applications
•    Mobile device security solutions for OEMs and carriers
•    Enterprise mobile device management (MDM) platforms
•    Secure smartphones for government and defense sectors
•    Anti-malware software suites for Android
•    Telecom infrastructure security services
Benefits/Advantages
•    First inline defense at the RIL layer with real-time mitigation
•    Broad OS compatibility without hardware modification
•    Detects and mitigates six SMS attack types across four adversary models
•    Lightweight implementation with minimal battery and latency impact
•    Extensible policy language for adapting to emerging threats