DocumentCode
1846871
Title
Intent security testing: An Approach to testing the Intent-based vulnerability of Android components
Author
Salva, Sebastien ; Zafimiharisoa, Stassia R. ; Laurencot, Patrice
Author_Institution
LIMOS - UMR CNRS 6158, PRES Clermont-Ferrand University, Clermont-Ferrand, France
fYear
2013
fDate
29-31 July 2013
Firstpage
1
Lastpage
8
Abstract
The intent mechanism is a powerful feature of the Android platform that helps compose existing components together to build a Mobile application. However, hackers can leverage the intent messaging to extract personal data or to call components without credentials by sending malicious intents to components. This paper tackles this issue by proposing a security testing method which aims at detecting whether the components of an Android application are vulnerable to malicious intents. Our method takes Android projects and intent-based vulnerabilities formally represented with models called vulnerability patterns. The originality of our approach resides in the generation of partial specifications from configuration files and component codes to generate test cases. A tool, called APSET, is presented and evaluated with experimentations on some Android applications.
Keywords
Androids; Humanoid robots; Mobile communication; Security; Semantics; Suspensions; Testing; Android Applications; Model-based Testing; Security Testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Cryptography (SECRYPT), 2013 International Conference on
Conference_Location
Reykjavik, Iceland
Type
conf
Filename
7223185
Link To Document