...
首页> 外文期刊>Empirical Software Engineering >Are free Android app security analysis tools effective in detecting known vulnerabilities?
【24h】

Are free Android app security analysis tools effective in detecting known vulnerabilities?

机译:免费的Android应用安全分析工具是否可以有效检测已知漏洞?

获取原文
获取原文并翻译 | 示例
           

摘要

Increasing interest in securing the Android ecosystem has spawned numerous efforts to assist app developers in building secure apps. These efforts have resulted in tools and techniques capable of detecting vulnerabilities and malicious behaviors in apps. However, there has been no evaluation of the effectiveness of these tools and techniques in detecting known vulnerabilities. The absence of such evaluations puts app developers at a disadvantage when choosing security analysis tools to secure their apps. In this regard, we evaluated the effectiveness of vulnerability detection tools for Android apps. We reviewed 64 tools and empirically evaluated 14 vulnerability detection tools against 42 known unique vulnerabilities captured by Ghera benchmarks, which are composed of both vulnerable and secure apps. Of the 20 observations from the evaluation, the main observation is existing vulnerability detection tools for Android apps are very limited in their ability to detect known vulnerabilities - all of the evaluated tools together could only detect 30 of the 42 known unique vulnerabilities. More effort is required if security analysis tools are to help developers build secure apps. We hope the observations from this evaluation will help app developers choose appropriate security analysis tools and persuade tool developers and researchers to identify and address limitations in their tools and techniques. We also hope this evaluation will catalyze or spark a conversation in the software engineering and security communities to require a more rigorous and explicit evaluation of security analysis tools and techniques.
机译:对保护Android生态系统的兴趣日益浓厚,为协助应用程序开发人员构建安全的应用程序做出了许多努力。这些努力导致了能够检测应用程序中的漏洞和恶意行为的工具和技术。但是,尚未评估这些工具和技术在检测已知漏洞中的有效性。缺乏这种评估会使应用程序开发人员在选择安全分析工具来保护其应用程序时处于不利地位。在这方面,我们评估了Android应用程序漏洞检测工具的有效性。我们审查了64种工具,并针对Ghera基准测试捕获的42个已知的独特漏洞(包括脆弱的应用程序和安全的应用程序),对14种漏洞检测工具进行了经验评估。在评估的20个观察结果中,主要观察结果是,现有的Android应用程序漏洞检测工具在检测已知漏洞方面的能力非常有限-所有评估的工具总共只能检测出42个已知的独特漏洞中的30个。如果安全分析工具要帮助开发人员构建安全的应用程序,则需要付出更多的努力。我们希望这次评估的观察结果将有助于应用程序开发人员选择适当的安全分析工具,并说服工具开发人员和研究人员识别并解决其工具和技术方面的局限性。我们还希望该评估能够促进或引发软件工程和安全社区中的对话,以要求对安全分析工具和技术进行更严格和明确的评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号