Where Are We Looking for Security Concerns? Understanding Android Security Static Analysis

被引:0
|
作者
Schmeelk, Suzanna [1 ]
机构
[1] St Johns Univ, Queens, NY 11439 USA
来源
PROCEEDINGS OF THE FUTURE TECHNOLOGIES CONFERENCE (FTC) 2019, VOL 2 | 2020年 / 1070卷
关键词
Android mobile services; Static analysis; Cyber security; Software engineering; Networking; End user services; Weakness detection; Malware prevention; Malware mitigation; Malware detection; Mobile devices; NIST Bugs Framework (BF); Mitre CAPEC; Mitre CWE;
D O I
10.1007/978-3-030-32523-7_32
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Static analysis is a traditional technique for software transformation and type analysis. Recently, static analysis has become a technique to identify cyber security vulnerabilities and malware. Specifically, static analysis has been extended into the mobile-computing arena for security-related analyses. This research examines many top security papers that are published in major conferences, journals and technical reports, and characterizes the current research characterize static analysis research. The papers identified in this paper were selected based their high citings by top research or because they introduced either a novel analysis technique or a novel security issue analysis. This research systematically constructs a static analysis landscape by charting and characterizing analysis strengths and limitations in both accuracy and security threats. The findings are reported online at www.technologyinthepark.com. This research has identified two types of static analysis motivations which affect the soundness of an analysis methodology: techniques for analyzing software for vulnerabilities and techniques used to examine applications for malware. Building on earlier research, for completeness and to aid the community by providing a coverage map, this research has connected technique motivations found to Mitre's attack taxonomy, Mitre's vulnerability taxonomy as well as the National Institute of Standards and Technology's (NIST's) Bugs Framework (BF) taxonomy. The findings include identifying vulnerabilities which are not being systematically researched.
引用
收藏
页码:467 / 483
页数:17
相关论文
共 50 条
  • [1] Where are we looking? Understanding Android Static Analysis Techniques
    Schmeelk, Suzanna
    2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 384 - 385
  • [2] Research on Static Analysis Technology of Android Application Security Defects
    Chen, Lu
    Liu, Xing
    Ma, Yuan-yuan
    Shi, Cong-cong
    Li, Ni-ge
    2016 INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING AND AUTOMATION (ICEEA 2016), 2016,
  • [3] Meizodon: Security Benchmarking Framework for Static Android Malware Detectors
    Rodriguez, Sebastiaan Alvarez
    van der Kouwe, Erik
    THIRD CENTRAL EUROPEAN CYBERSECURITY CONFERENCE (CECC 2019), 2019,
  • [4] SANT: Static Analysis of Native Threads for Security Vetting of Android Applications
    Andarzian, Seyed Behnam
    Ladani, Behrouz Tork
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2022, 14 (01): : 13 - 25
  • [5] Static binary analysis of mobile applications for the android platform, according to the requirements of information security
    Aleksandrov Y.A.
    Safin L.K.
    Troshina K.N.
    Chernov A.V.
    Moscow University Computational Mathematics and Cybernetics, 2016, 40 (3) : 141 - 146
  • [6] Dynamic Security Analysis on Android: A Systematic Literature Review
    Sutter, Thomas
    Kehrer, Timo
    Rennhard, Marc
    Tellenbach, Bernhard
    Klein, Jacques
    IEEE ACCESS, 2024, 12 : 57261 - 57287
  • [7] Security in Social Networking Services: A Value-Focused Thinking Exploration in Understanding Users' Privacy and Security Concerns
    Barrett-Maitland, Nadine
    Barclay, Corlane
    Osei-Bryson, Kweku-Muata
    INFORMATION TECHNOLOGY FOR DEVELOPMENT, 2016, 22 (03) : 464 - 486
  • [8] ALETHEIA: Improving the Usability of Static Security Analysis
    Tripp, Omer
    Guarnieri, Salvatore
    Pistoia, Marco
    Aravkin, Aleksandr
    CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, : 762 - 774
  • [9] Evaluation of Static Analysis Tools for Software Security
    AlBreiki, Hamda Hasan
    Mahmoud, Qusay H.
    2014 10TH INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION TECHNOLOGY (IIT), 2014, : 93 - 98
  • [10] Using Static Analysis for Enhancing HLS Security
    Collini, Luca
    Ah-Kiow, Joey
    Pilato, Christian
    Karri, Ramesh
    Tan, Benjamin
    IEEE EMBEDDED SYSTEMS LETTERS, 2024, 16 (02) : 166 - 169