首页> 外文会议>Iberian Conference on Information Systems and Technologies >A technique for evaluation and detection of potentially vulnerable code in Android applications
【24h】

A technique for evaluation and detection of potentially vulnerable code in Android applications

机译:一种用于评估和检测Android应用程序中潜在漏洞代码的技术

获取原文

摘要

Searching for vulnerabilities in Android apps through approaches based on the app's dex bytecode has been applied to a lot of researches. This approach, called late detection, is applied to apps already released, and usually doesn't identify vulnerabilities before users have been exposed. This article presents a method based on static analysis with matching patterns for identifying these vulnerabilities beforehand, during the app development, avoiding users' exposure. The presented technique was evaluated by an experimental test proofapplied to open-source applications, analyzed by appDroidAnalyzer, identifying dozens of apps affected by vulnerabilities in their source code.
机译:通过基于应用程序的dex字节码的方法搜索Android应用程序中的漏洞已被用于许多研究。这种称为延迟检测的方法适用于已经发布的应用程序,通常在用户暴露之前无法识别漏洞。本文介绍了一种基于静态分析和匹配模式的方法,该方法可在应用程序开发期间预先识别这些漏洞,从而避免用户暴露。通过应用到开源应用程序的实验测试证明对提出的技术进行了评估,并通过appDroidAnalyzer进行了分析,从而确定了数十个受其源代码漏洞影响的应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号