DocumentCode
3705302
Title
A fuzzing test for dynamic vulnerability detection on Android Binder mechanism
Author
Wang Kai; Zhang Yuqing; Liu Qixu; Fan Dan
Author_Institution
National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing, China
fYear
2015
Firstpage
709
Lastpage
710
Abstract
Binder, which helps to package the functional codes of system processes into inter-process invocable interfaces for application-level processes, is the core mechanism to implement the Inter-Process Communication(IPC) in Android. This paper, for the first time, attempts to study the system-level security properties of this mechanism. The universal injection interface and the model of IPC data are proposed to implement a fuzzing test. A test case generation technique based on mutation algorithm of pre-captured IPC data is introduced in order to improve the fuzzing test efficiency. Two high-risk vulnerabilities are detected in Android 5.1.0. Analysis of these vulnerabilities highlights a critical design issue in the system services of Binder mechanism.
Keywords
"Androids","Humanoid robots","Data models","Algorithm design and analysis","Servers","Computer crime"
Publisher
ieee
Conference_Titel
Communications and Network Security (CNS), 2015 IEEE Conference on
Type
conf
DOI
10.1109/CNS.2015.7346897
Filename
7346897
Link To Document