DroidPatrol: A Static Analysis Plugin For Secure Mobile Software Development

被引:6
|
作者
Talukder, Md Arabin Islam [1 ]
Shahriar, Hossain [1 ]
Qian, Kai [1 ]
Rahman, Mohammad [2 ]
Ahamed, Sheikh [3 ]
Wu, Fan [4 ]
Agu, Emmanuel [5 ]
机构
[1] Kennesaw State Univ, Marietta, GA 30060 USA
[2] Florida Int Univ, Miami, FL 33199 USA
[3] Marquette Univ, Milwaukee, WI 53233 USA
[4] Tuskegee Univ, Tuskegee, AL 36088 USA
[5] Worcester Polytech Inst, Worcester, MA 01609 USA
来源
2019 IEEE 43RD ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1 | 2019年
基金
美国国家科学基金会;
关键词
Android; Secure software development; Static analysis; Tainted data flow; SQL Injection;
D O I
10.1109/COMPSAC.2019.00087
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
While the number of mobile applications are rapidly growing, these applications are often coming with numerous security flaws due to the lack of appropriate coding practices. Security issues must be addressed earlier in the development lifecycle rather than fixing them after the attacks because the damage might already be extensive. Early elimination of possible security vulnerabilities will help us increase the security of our software and mitigate or reduce the potential damages through data losses or service disruptions caused by malicious attacks. However, many software developers lack necessary security knowledge and skills required at the development stage, and Secure Mobile Software Development (SMSD) is not yet well represented in academia and industry. In this paper, we present a static analysis-based security analysis approach through design and implementation of a plugin for Android Development Studio, namely DroidPatrol. The proposed plugins can support developers by providing list of potential vulnerabilities early.
引用
收藏
页码:565 / 569
页数:5
相关论文
共 50 条
  • [1] Secure Mobile Software Development with Vulnerability Detectors in Static Code Analysis
    Meng, Xianyong
    Qian, Kai
    Lo, Dan
    Bhattacharya, Prabir
    Wu, Fan
    2018 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2018), 2018,
  • [2] Static Analysis-Based Approaches for Secure Software Development
    Siavvas, Miltiadis
    Gelenbe, Erol
    Kehagias, Dionysios
    Tzovaras, Dimitrios
    SECURITY IN COMPUTER AND INFORMATION SCIENCES, EURO-CYBERSEC 2018, 2018, 821 : 142 - 157
  • [3] Static Vulnerability Analysis for Secure Mobile Platforms
    Kalyanasundaram, Dhinakar
    D'Souza, Meenakshi
    PROCEEDINGS OF THE 10TH INNOVATIONS IN SOFTWARE ENGINEERING CONFERENCE, 2017, : 195 - 201
  • [4] Secure Mobile IPC Software Development with Vulnerability Detectors in Android Studio
    Meng, Xianyong
    Qian, Kai
    Lo, Dan
    Shahriar, Hossain
    Talukder, M. D. Arabin Islam
    Bhattacharya, Prabir
    2018 IEEE 42ND ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2018, : 829 - 830
  • [5] Labware for Secure Mobile Software Development (SMSD) Education
    Qian, Kai
    Shahriar, Hossain
    Wu, Fan
    Tao, Lixin
    Bhattacharya, Prabir
    ITICSE'17: PROCEEDINGS OF THE 2017 ACM CONFERENCE ON INNOVATION AND TECHNOLOGY IN COMPUTER SCIENCE EDUCATION, 2017, : 375 - 375
  • [6] Do Static Analysis Tools Improve Awareness and Attitude Toward Secure Software Development?
    Nocera, Sabato
    Romano, Simone
    Di Nucci, Dario
    Francese, Rita
    Palomba, Fabio
    Scanniello, Giuseppe
    QUALITY OF INFORMATION AND COMMUNICATIONS TECHNOLOGY, QUATIC 2024, 2024, 2178 : 399 - 407
  • [7] Adherence to Secure Software Development Lifecycle
    Omar, Alaa'
    Alsadeh, Ahmad
    Nawahdah, Mamoun
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON SOFTWARE TECHNOLOGIES (ICSOFT), 2022, : 410 - 417
  • [8] Cybersecurity Through Secure Software Development
    Josang, Audun
    Odegaard, Marte
    Oftedal, Erlend
    INFORMATION SECURITY EDUCATION ACROSS THE CURRICULUM, WISE 9, 2015, 453 : 53 - 63
  • [9] Detecting Software Vulnerabilities in Android Using Static Analysis
    Dhaya, R.
    Poongodi, M.
    2014 INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION CONTROL AND COMPUTING TECHNOLOGIES (ICACCCT), 2014, : 915 - 918
  • [10] Security Considerations for the Development of Secure Software Systems
    Ruggieri, Maxwell
    Hsu, Tzu-Tang
    Ali, Md Liakat
    2019 IEEE 10TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2019, : 1187 - 1193