APSET, an Android aPplication SEcurity Testing tool for detecting intent-based vulnerabilities

被引:0
|
作者
Sébastien Salva
Stassia R. Zafimiharisoa
机构
[1] University of Auvergne,LIMOS
[2] Blaise Pascal University,UMR CNRS 6158
关键词
Security testing; Model-based testing; Android applications; Intent mechanism;
D O I
暂无
中图分类号
学科分类号
摘要
The Android messaging system, called intent, is a mechanism that ties components together to build applications for smartphones. Intents are kinds of messages composed of actions and data, sent by a component to another component to perform several operations, e.g. launching a user interface. The intent mechanism offers a lot of flexibility for developing Android applications, but it might also be used as an entry point for security attacks. The latter can be easily sent with intents to components, that can indirectly forward attacks to other components and so on. In this context, this paper proposes APSET, a tool for Android aPplication SEcurity Testing, which aims at detecting intent-based vulnerabilities. It takes as inputs Android applications and intent-based vulnerabilities formally expressed with models called vulnerability patterns. Then, and this is the originality of our approach, class diagrams and partial specifications are automatically generated from applications with algorithms reflecting some knowledge of the Android documentation. These partial specifications avoid false positives and refine the test result with special verdicts notifying that a component is not compliant to its specification. Furthermore, we propose a test case execution framework which supports the receipt of any exception, the detection of application crashes, and provides a final XML test report detailing the test case verdicts. The vulnerability detection effectiveness of APSET is evaluated with experimentations on randomly chosen Android applications of the Android Market.
引用
收藏
页码:201 / 221
页数:20
相关论文
共 50 条
  • [41] Research on Detecting Windows Vulnerabilities Based on Security Patch Comparison
    Guo, Hui
    Wang, Yong-yi
    Pan, Zu-lie
    Liu, Shi-wei
    PROCEEDINGS OF 2016 SIXTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION & MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2016), 2016, : 366 - 369
  • [42] SEBASTiAn: A static and extensible black-box application security testing tool for iOS and Android applications
    Pagano, Francesco
    Romdhana, Andrea
    Caputo, Davide
    Verderame, Luca
    Merlo, Alessio
    SOFTWAREX, 2023, 23
  • [43] Intent-based Application and Network Cooperative Control Technology for Video-streaming Services
    Kawano T.
    Kobayashi M.
    NTT Technical Review, 2022, 20 (09): : 64 - 69
  • [44] Vulnerabilities mapping based on OWASP-SANS: A survey for static application security testing (SAST)
    Li J.
    Annals of Emerging Technologies in Computing, 2020, 4 (03) : 1 - 8
  • [45] Intent-Based Path Selection for VM Migration Application with Open Network Operating System
    Marenda, Dimas A.
    Suranegara, Galura M.
    Risdianto, Aris C.
    Hakimi, Rifqy
    Mulyana, Eueung
    PROCEEDINGS OF 2018 4TH INTERNATIONAL CONFERENCE ON WIRELESS AND TELEMATICS (ICWT), 2018,
  • [46] Demo: Intent-Based 5G IoT Application Network Slice Deployment
    Aklamanu, Fred
    Randriamasy, Sabine
    Renault, Eric
    PROCEEDINGS OF THE 2019 10TH INTERNATIONAL CONFERENCE ON NETWORKS OF THE FUTURE (NOF 2019), 2019, : 141 - 143
  • [47] Demo: Intent-Based 5G IoT Application Slice Energy Monitoring
    Aklamanu, Fred
    Randriamasy, Sabine
    Renault, Eric
    Latif, Imran
    Hebbar, Abdelkrim
    Conte, Alberto
    Al Jammal, Bilal
    Hamdaoui, Warda
    2018 IFIP NETWORKING CONFERENCE (IFIP NETWORKING) AND WORKSHOPS, 2018, : A5 - A6
  • [48] Pixy: A static analysis tool for detecting Web application vulnerabilities - (Short paper)
    Jovanovic, Nenad
    Kruegel, Christopher
    Kirda, Engin
    2006 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2006, : 258 - +
  • [49] A Static Analysis Tool for Detecting Web Application Injection Vulnerabilities for ASP Program
    Zhang Xin-hua
    Wang Zhi-jian
    2010 2ND INTERNATIONAL CONFERENCE ON E-BUSINESS AND INFORMATION SYSTEM SECURITY (EBISS 2010), 2010, : 116 - 120
  • [50] Intent-Based Orchestration for Application Relocation in a 5G Cloud-native Platform
    Barrachina-Munoz, Sergio
    Baranda, Jorge
    Payaro, Miquel
    Mangues-Bafalluy, Josep
    2022 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (IEEE NFV-SDN), 2022, : 94 - 95