DocumentCode
1804041
Title
Data vulnerability detection by security testing for Android applications
Author
Salva, Sebastien ; Zafimiharisoa, Stassia R.
Author_Institution
LIMOS, Auvergne Univ., Clermont-Ferrand, France
fYear
2013
fDate
14-16 Aug. 2013
Firstpage
1
Lastpage
8
Abstract
The Android intent messaging is a mechanism that ties components together to build Mobile applications. Intents are kinds of messages composed of actions and data, sent by a component to another component to perform several operations, e.g., launching a user interface. The intent mechanism eases the writing of Mobile applications, but it might also be used as an entry point for security attacks. The latter can be easily sent with intents to components, that can indirectly forward attacks to other components and so on. In this context, this paper proposes a Model-based security testing approach to attempt to detect data vulnerabilities in Android applications. In other words, this approach generates test cases to check whether components are vulnerable to attacks, sent through intents, that expose personal data. Our method takes Android applications and intent-based vulnerabilities formally expressed with models called vulnerability patterns. Then, and this is the originality of our approach, partial specifications are automatically generated from configuration files and component codes. Test cases are then automatically generated from vulnerability patterns and the previous specifications. A tool, called APSET, is presented and evaluated with experimentations on some Android applications.
Keywords
formal specification; mobile computing; program testing; security of data; APSET; Android applications; Android intent messaging; component codes; configuration files; data vulnerability detection; intent mechanism; intent-based vulnerabilities; mobile applications; model-based security testing approach; partial specifications; security attacks; vulnerability patterns; Androids; Documentation; Humanoid robots; Security; Semantics; Suspensions; Testing; Android applications; Mobile device security; Model-based testing; Security testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Security for South Africa, 2013
Conference_Location
Johannesburg
Type
conf
DOI
10.1109/ISSA.2013.6641043
Filename
6641043
Link To Document