首页> 外文OA文献 >Making DidFail Succeed: Enhancing the CERT Static Taint Analyzer for Android App Sets
【2h】

Making DidFail Succeed: Enhancing the CERT Static Taint Analyzer for Android App Sets

机译:使DidFail成功:增强适用于Android应用程序集的CERT静态污染分析器

摘要

This report describes recent significant enhancements to DidFail (Droid Intent Data Flow Analysis for Information Leakage), the CERT static taint analyzer for sets of Android apps. In addition to improving the analyzer itself, the enhancements include a new testing framework, new test apps, and test results. A framework for testing the DidFail analyzer, including a setup for cloud-based testing was developed and instrumented to measure performance. Cloud-based testing enables the parallel use of powerful, commercially available virtual machines to speed up testing. DidFail was also modified to use the most current version of FlowDroid and Soot, increasing its success rate from 18% to 68% on our test set of real-world apps. Analytical features were added for more types of components and shared static fields and new apps developed to test these features. The improved DidFail analyzer and the cloud-based testing framework were used to test the new apps and additional apps from the Google Play store.
机译:本报告介绍了对DidFail(用于信息泄漏的Droid意图数据流分析)的最新重大增强功能,DidFail是用于Android应用程序集合的CERT静态污染分析器。除了改进分析仪本身之外,增强功能还包括新的测试框架,新的测试应用程序和测试结果。开发了用于测试DidFail分析器的框架,包括用于基于云的测试的设置,并对其进行了测量性能的测量。基于云的测试可以并行使用功能强大的商用虚拟机来加快测试速度。 DidFail还进行了修改,以使用最新版本的FlowDroid和Soot,在我们的真实应用程序测试集上,其成功率从18%提高到68%。为更多类型的组件和共享的静态字段添加了分析功能,并开发了新的应用程序来测试这些功能。改进的DidFail分析器和基于云的测试框架用于测试Google Play商店中的新应用程序和其他应用程序。

著录项

相似文献

  • 外文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号