• DocumentCode
    1804041
  • Title

    Data vulnerability detection by security testing for Android applications

  • Author

    Salva, Sebastien ; Zafimiharisoa, Stassia R.

  • Author_Institution
    LIMOS, Auvergne Univ., Clermont-Ferrand, France
  • fYear
    2013
  • fDate
    14-16 Aug. 2013
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    The Android intent messaging is a mechanism that ties components together to build Mobile applications. Intents are kinds of messages composed of actions and data, sent by a component to another component to perform several operations, e.g., launching a user interface. The intent mechanism eases the writing of Mobile applications, but it might also be used as an entry point for security attacks. The latter can be easily sent with intents to components, that can indirectly forward attacks to other components and so on. In this context, this paper proposes a Model-based security testing approach to attempt to detect data vulnerabilities in Android applications. In other words, this approach generates test cases to check whether components are vulnerable to attacks, sent through intents, that expose personal data. Our method takes Android applications and intent-based vulnerabilities formally expressed with models called vulnerability patterns. Then, and this is the originality of our approach, partial specifications are automatically generated from configuration files and component codes. Test cases are then automatically generated from vulnerability patterns and the previous specifications. A tool, called APSET, is presented and evaluated with experimentations on some Android applications.
  • Keywords
    formal specification; mobile computing; program testing; security of data; APSET; Android applications; Android intent messaging; component codes; configuration files; data vulnerability detection; intent mechanism; intent-based vulnerabilities; mobile applications; model-based security testing approach; partial specifications; security attacks; vulnerability patterns; Androids; Documentation; Humanoid robots; Security; Semantics; Suspensions; Testing; Android applications; Mobile device security; Model-based testing; Security testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security for South Africa, 2013
  • Conference_Location
    Johannesburg
  • Type

    conf

  • DOI
    10.1109/ISSA.2013.6641043
  • Filename
    6641043