Architectural approaches to network shielding in Android and iOSoperating systems: a comparative analysis of the kernel, systemextensions, and application levels

Main Article Content

Оlexander V. Zadereyko
Volodymyr І. Hura
Oleksandr A. Blazhko
Anatoliy Yu. Gaida

Abstract

This article is devoted to a comparative analysis of the architectural solutions underlying network filtering in the Android and iOS operating systems. The relevance of this research stems from the dominant position of these two operating systems in the mobile communications device market and the fundamental differences in their architectural organization, which determine the capabilities and limitations of third-party tools for controlling network connections. It has been established that the network filtering architecture of the Android operating system, based on the Netfilter/iptables module and the extended Berkeley Packet Filter technology, is covered in considerable detail in scientific publications, whereas the network filtering architecture of the iOS operating system—specifically the NetworkExtension framework (along with the XNU kernel’s PF system packet filter and the utun tunneling interface)—is addressed only fragmentarily in existing studies, generally within the context of security characteristics, without being singled out as a separate subject of analysis. To address this identified gap, a systematic decomposition of the architectures of both operating systems was performed at comparable levels—the kernel, system services and extensions, and user applications. It is shown that the Android operating system’s network firewall is implemented using three architectural models: One is based on Netfilter/iptables/eBPF, another is based on eBPF as part of the Android Open Source Project, and the third is based on the unprivileged VpnService software interface. In contrast, in the iOS operating system, firewall functions are distributed among the configuration and execution modules of the NetworkExtension framework (NEFilterManager, NEFilterProviderConfiguration, NEFilterDataProvider, NEFilterControlProvider), and the enforcement of rules is carried out via the utun system tunnel interface. It has been determined that architectural differences between the operating systems manifest at three levels: kernel openness, the number and specialization of extension points for third-party developers, and the model of execution isolation for filtering code. A limitation common to both operating systems is the inability to run multiple independent network filters simultaneously. A decomposition model is proposed that symmetrically reflects the network filtering architecture of both operating systems at comparable levels. The results of this architectural decomposition form the basis for the further development of a unified methodology and a system of criteria for the comparative analysis of network filters in the Android and iOS operating systems.


 

Downloads

Download data is not yet available.

Article Details

Section

Informatics and intelligent information technologies

Author Biographies

Оlexander V. Zadereyko, Національний університет «Одеська юридична академія», Фонтанська дорога, 23. Одеса, 65009, Україна

PhD, Associate Professor, Department of Artificial Intelligence and Mathematical Modeling.

Volodymyr І. Hura, Національний університет «Одеська юридична академія», Фонтанська дорога, 23. Одеса, 65009, Україна

PhD, Associate Professor, Department of Artificial Intelligence and Mathematical Modeling.

Oleksandr A. Blazhko, Національний університет «Одеська політехніка», пр. Шевченка, 1. Одеса, 65044, Україна

PhD, Associate Professor, Department of Software Engineering. 

Scopus Author ID: 57195410976

Anatoliy Yu. Gaida, Національний університет кораблебудування імені адмірала Макарова, пр. Центральний 3, Миколаїв, 54000, Україна

PhD, Associate Professor, Department of Information Management Systems and Technologies

How to Cite

Architectural approaches to network shielding in Android and iOSoperating systems: a comparative analysis of the kernel, systemextensions, and application levels. (2026). Informatics. Culture. Technology, 3(1 (3), 58–74. https://doi.org/10.15276/ict.03.2026.05

References