首页> 外文会议>Automation of Software Test (AST), 2012 7th International Workshop on >A whitebox approach for automated security testing of Android applications on the cloud
【24h】

A whitebox approach for automated security testing of Android applications on the cloud

机译:一种白盒方法,用于在云上对Android应用程序进行自动安全性测试

获取原文
获取原文并翻译 | 示例

摘要

By changing the way software is delivered to end-users, markets for mobile apps create a false sense of security: apps are downloaded from a market that can potentially be regulated. In practice, this is far from truth and instead, there has been evidence that security is not one of the primary design tenets for the mobile app stores. Recent studies have indicated mobile markets are harboring apps that are either malicious or vulnerable leading to compromises of millions of devices. The key technical obstacle for the organizations overseeing these markets is the lack of practical and automated mechanisms to assess the security of mobile apps, given that thousands of apps are added and updated on a daily basis. In this paper, we provide an overview of a multi-faceted project targeted at automatically testing the security and robustness of Android apps in a scalable manner. We describe an Android-specific program analysis technique capable of generating a large number of test cases for fuzzing an app, as well as a test bed that given the generated test cases, executes them in parallel on numerous emulated Androids running on the cloud.
机译:通过更改将软件交付给最终用户的方式,移动应用程序市场会产生一种错误的安全感:从可能受到监管的市场下载应用程序。实际上,这远非事实,相反,有证据表明,安全性不是移动应用程序商店的主要设计原则之一。最近的研究表明,移动市场上藏有恶意或易受攻击的应用程序,这些应用程序导致了数百万台设备的受损。鉴于每天要添加和更新成千上万的应用程序,因此组织监督这些市场的主要技术障碍是缺乏实用和自动化的机制来评估移动应用程序的安全性。在本文中,我们提供了一个多方面项目的概述,该项目旨在以可扩展的方式自动测试Android应用程序的安全性和健壮性。我们描述了一种特定于Android的程序分析技术,该技术能够生成大量的测试用例以模糊应用程序,并提供给出生成的测试用例的测试平台,并在云上运行的许多模拟Android上并行执行它们。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号