• DocumentCode
    1999219
  • Title

    A Distributed Multi-Target Software Vulnerability Discovery and Analysis Infrastructure for Smart Phones

  • Author

    Krishnan, S.P.T. ; Hao, Lee Wang ; Sathya, S.A. ; Devi, Lavany

  • Author_Institution
    Inst. for Infocomm Res., Singapore, Singapore
  • fYear
    2010
  • fDate
    6-10 Dec. 2010
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Smart phones of today have increasingly sophisticated software. As the feature set grows further, the probability of system security related defects is likely to increase as well. Today, the security of mobile platforms and applications comes under great scrutiny as they are getting widely adopted. It is therefore crucial that code for mobile devices gets well tested and security bugs eliminated where possible. A popular and effective testing technique to identify severe security bugs in source code is fuzz testing. However, it is extremely time consuming to generate randomized input and test them on each version of the mobile phone and its software. This paper presents, MAFIA - Multi-target Automated Fuzzing Infrastructure and Arsenal, a composite, distributed client-server fuzz testing infrastructure for software applications and libraries in virtually any smartphone platform. The set of tools in MAFIA is file-format agnostic and can be used across various applications & libraries. With MAFIA, we conducted a large number of tests against image-handling libraries and logged more than 13,000 mutated inputs that successfully crash several Symbian OS retail phones models. The system is scalable and can be easily extended to be used on new devices and operating systems.
  • Keywords
    mobile computing; mobile handsets; operating systems (computers); security of data; source coding; telecommunication computing; MAFIA; OS retail phones models; analysis infrastructure; distributed multitarget software vulnerability discovery; fuzz testing; image-handling libraries; mobile devices; mobile platforms; multitarget automated fuzzing infrastructure and arsenal; operating systems; security bugs; smart phones; source code; system security; Computer crashes; Libraries; Mobile communication; Mobile handsets; Security; Servers; Software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Telecommunications Conference (GLOBECOM 2010), 2010 IEEE
  • Conference_Location
    Miami, FL
  • ISSN
    1930-529X
  • Print_ISBN
    978-1-4244-5636-9
  • Electronic_ISBN
    1930-529X
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2010.5684011
  • Filename
    5684011