Title :
A whitebox approach for automated security testing of Android applications on the cloud
Author :
Mahmood, Riyadh ; Esfahani, Naeem ; Kacem, Thabet ; Mirzaei, Nariman ; Malek, Sam ; Stavrou, Angelos
Author_Institution :
Comput. Sci. Dept., George Mason Univ., Mason, OH, USA
Abstract :
By changing the way software is delivered to end-users, markets for mobile apps create a false sense of security: apps are downloaded from a market that can potentially be regulated. In practice, this is far from truth and instead, there has been evidence that security is not one of the primary design tenets for the mobile app stores. Recent studies have indicated mobile markets are harboring apps that are either malicious or vulnerable leading to compromises of millions of devices. The key technical obstacle for the organizations overseeing these markets is the lack of practical and automated mechanisms to assess the security of mobile apps, given that thousands of apps are added and updated on a daily basis. In this paper, we provide an overview of a multi-faceted project targeted at automatically testing the security and robustness of Android apps in a scalable manner. We describe an Android-specific program analysis technique capable of generating a large number of test cases for fuzzing an app, as well as a test bed that given the generated test cases, executes them in parallel on numerous emulated Androids running on the cloud.
Keywords :
cloud computing; mobile computing; program testing; security of data; Android applications; Android specific program analysis technique; automated mechanisms; automated security testing; cloud computing; harboring apps; mobile app stores; mobile markets; multifaceted project; technical obstacle; whitebox approach; Androids; Humanoid robots; Layout; Security; Smart phones; Software; Testing; Android; Program Analysis; Security Testing;
Conference_Titel :
Automation of Software Test (AST), 2012 7th International Workshop on
Conference_Location :
Zurich
Print_ISBN :
978-1-4673-1821-1
DOI :
10.1109/IWAST.2012.6228986