Title :
Intent security testing: An Approach to testing the Intent-based vulnerability of Android components
Author :
Salva, Sebastien ; Zafimiharisoa, Stassia R. ; Laurencot, Patrice
Author_Institution :
LIMOS - UMR CNRS 6158, PRES Clermont-Ferrand University, Clermont-Ferrand, France
Abstract :
The intent mechanism is a powerful feature of the Android platform that helps compose existing components together to build a Mobile application. However, hackers can leverage the intent messaging to extract personal data or to call components without credentials by sending malicious intents to components. This paper tackles this issue by proposing a security testing method which aims at detecting whether the components of an Android application are vulnerable to malicious intents. Our method takes Android projects and intent-based vulnerabilities formally represented with models called vulnerability patterns. The originality of our approach resides in the generation of partial specifications from configuration files and component codes to generate test cases. A tool, called APSET, is presented and evaluated with experimentations on some Android applications.
Keywords :
Androids; Humanoid robots; Mobile communication; Security; Semantics; Suspensions; Testing; Android Applications; Model-based Testing; Security Testing;
Conference_Titel :
Security and Cryptography (SECRYPT), 2013 International Conference on
Conference_Location :
Reykjavik, Iceland