【24h】

Profiling Android Vulnerabilities

机译:分析Android漏洞

获取原文

摘要

In widely used mobile operating systems a single vulnerability can threaten the security and privacy of billions of users. Therefore, identifying vulnerabilities and fortifying software systems requires constant attention and effort. However, this is costly and it is almost impossible to analyse an entire code base. Thus, it is necessary to prioritize efforts towards the most likely vulnerable areas. A first step in identifying these areas is to profile vulnerabilities based on previously reported ones. To investigate this, we performed a manual analysis of Android vulnerabilities, as reported in the National Vulnerability Database for the period 2008 to 2014. In our analysis, we identified a comprehensive list of issues leading to Android vulnerabilities. We also point out characteristics of the locations where vulnerabilities reside, the complexity of these locations and the complexity to fix the vulnerabilities. To enable future research, we make available all of our data.
机译:在广泛使用的移动操作系统中,单个漏洞可以威胁数十亿用户的安全和隐私。因此,识别漏洞并加强软件系统需要不断的关注和努力。但是,这很昂贵,几乎不可能分析整个代码库。因此,有必要优先考虑对最可能的脆弱地区的努力。识别这些区域的第一步是根据先前报告的漏洞来分析漏洞。为了对此进行调查,我们对Android漏洞进行了手动分析,如2008年至2014年期间的国家漏洞数据库中所述。在我们的分析中,我们确定了导致Android漏洞的全面问题列表。我们还指出了漏洞所在位置的特征,这些位置的复杂性以及修复漏洞的复杂性。为了进行进一步的研究,我们提供了所有数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号