【24h】

SAM: The Static Analysis Module of the MAVERIC Mobile App Security Verification Platform

机译:SAM:MAVERIC移动应用程序安全验证平台的静态分析模块

获取原文

摘要

The tremendous success of the mobile application paradigm is due to the ease with which new applications are uploaded by developers, distributed through the application markets (e.g. Google Play), and finally installed by the users. Yet, the very same model is causing serious security concerns, since users have no or little means to ascertain the trustworthiness of the applications they install on their devices. To protect their customers, Poste Italiane has defined the Mobile Application Verification Cluster (MAVERIC), a process for the systematic security analysis of third-party mobile apps that leverage the online services provided by the company (e.g. home banking, parcel tracking). We present SAM, a toolkit that supports this process by automating a number of operations including reverse engineering, privilege analysis, and automatic verification of security properties. We introduce the functionalities of SAM through a demonstration of the platform applied to real Android applications.
机译:移动应用程序范例的巨大成功是由于开发人员轻松上传新应用程序,通过应用程序市场(例如Google Play)进行分发并最终由用户安装。但是,由于用户没有或几乎没有办法确定安装在其设备上的应用程序的可信赖性,因此同一模型也引起了严重的安全隐患。为了保护客户,Poste Italiane定义了移动应用程序验证集群(MAVERIC),该程序是对利用公司提供的在线服务(例如家庭银行业务,包裹跟踪)的第三方移动应用程序进行系统安全性分析的过程。我们介绍了SAM,它是一种通过自动化许多操作(包括逆向工程,特权分析和安全性自动验证)来支持此过程的工具包。我们通过演示适用于实际Android应用程序的平台来介绍SAM的功能。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号