• DocumentCode
    3705302
  • Title

    A fuzzing test for dynamic vulnerability detection on Android Binder mechanism

  • Author

    Wang Kai; Zhang Yuqing; Liu Qixu; Fan Dan

  • Author_Institution
    National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing, China
  • fYear
    2015
  • Firstpage
    709
  • Lastpage
    710
  • Abstract
    Binder, which helps to package the functional codes of system processes into inter-process invocable interfaces for application-level processes, is the core mechanism to implement the Inter-Process Communication(IPC) in Android. This paper, for the first time, attempts to study the system-level security properties of this mechanism. The universal injection interface and the model of IPC data are proposed to implement a fuzzing test. A test case generation technique based on mutation algorithm of pre-captured IPC data is introduced in order to improve the fuzzing test efficiency. Two high-risk vulnerabilities are detected in Android 5.1.0. Analysis of these vulnerabilities highlights a critical design issue in the system services of Binder mechanism.
  • Keywords
    "Androids","Humanoid robots","Data models","Algorithm design and analysis","Servers","Computer crime"
  • Publisher
    ieee
  • Conference_Titel
    Communications and Network Security (CNS), 2015 IEEE Conference on
  • Type

    conf

  • DOI
    10.1109/CNS.2015.7346897
  • Filename
    7346897