首页> 外文会议>International Conference on Measuring Technology and Mechatronics Automation >Research and Implementation of Mobile Application Security Detection Combining Static and Dynamic
【24h】

Research and Implementation of Mobile Application Security Detection Combining Static and Dynamic

机译:静态与动态相结合的移动应用安全检测的研究与实现

获取原文

摘要

With the popularity of the Internet and mobile intelligent terminals, the number of mobile applications is exploding. Mobile intelligent terminals trend to be the mainstream way of people's work and daily life online in place of PC terminals. Mobile application system brings some security problems inevitably while it provides convenience for people, and becomes a main target of hackers. Therefore, it is imminent to strengthen the security detection of mobile applications. This paper divides mobile application security detection into client security detection and server security detection. We propose a combining static and dynamic security detection method to detect client-side. We provide a method to get network information of server by capturing and analyzing mobile application traffic, and propose a fuzzy testing method based on HTTP protocol to detect server-side security vulnerabilities. Finally, on the basis of this, an automated platform for security detection of mobile application system is developed. Experiments show that the platform can detect the vulnerabilities of mobile application client and server effectively, and realize the automation of mobile application security detection. It can also reduce the cost of mobile security detection and enhance the security of mobile applications.
机译:随着Internet和移动智能终端的普及,移动应用程序的数量呈爆炸式增长。移动智能终端已取代PC终端,成为人们在线工作和日常生活的主流方式。移动应用系统在给人们带来便利的同时,不可避免地带来一些安全问题,成为黑客的主要攻击目标。因此,迫切需要加强对移动应用程序的安全检测。本文将移动应用程序安全性检测分为客户端安全性检测和服务器安全性检测。我们提出了一种结合静态和动态安全性检测方法来检测客户端的方法。我们提供了一种通过捕获和分析移动应用程序流量来获取服务器网络信息的方法,并提出了一种基于HTTP协议的模糊测试方法来检测服务器端的安全漏洞。最后,在此基础上,开发了用于移动应用系统安全检测的自动化平台。实验表明,该平台可以有效地检测出移动应用客户端和服务器的漏洞,实现了移动应用安全检测的自动化。它还可以降低移动安全检测的成本,并增强移动应用程序的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号