首页    期刊浏览 2024年07月05日 星期五
登录注册

文章基本信息

  • 标题:A Model Guided Security Analysis Approach for Android Applications
  • 本地全文:下载
  • 作者:Yan Zhang ; Zhoujun Li ; Dianfu Ma
  • 期刊名称:Journal of Software
  • 印刷版ISSN:1796-217X
  • 出版年度:2016
  • 卷号:11
  • 期号:7
  • 页码:677-684
  • DOI:10.17706/jsw.11.7.677-684
  • 出版社:Academy Publisher
  • 摘要:Revealing security vulnerabilities is one of great challenges for the Android ecosystem. Static analysis is the usual approach of the security analysis for computer software. However, it is undirected and time-consuming for the common static analysis methods to analyze the entire Android application system-atically from the main entry point. In order to adapt to the event-driven feature of Android applications, a model guided security analysis approach for Android applications is introduced and implemented into the prototype tool MSAS. This approach builds and utilizes the Operation Security Model to guide the targeted analysis process, and then concentrate on the identified analysis surface to reduce analysis workload, thereby achieving fast analysis speed and on-demand code coverage based on the security rules. The test result shows that this approach can improve the efficiency and effect of security analysis for Android appli-cations, and it has revealed 11 security vulnerabilities by analyzing several popular Android applications.
  • 其他关键词:Model guided analysis, security analysis, Android application security, static analysis, vulnerability discovery
国家哲学社会科学文献中心版权所有