DroidPatrol: A Static Analysis Plugin For Secure Mobile Software Development

被引:6
|
作者
Talukder, Md Arabin Islam [1 ]
Shahriar, Hossain [1 ]
Qian, Kai [1 ]
Rahman, Mohammad [2 ]
Ahamed, Sheikh [3 ]
Wu, Fan [4 ]
Agu, Emmanuel [5 ]
机构
[1] Kennesaw State Univ, Marietta, GA 30060 USA
[2] Florida Int Univ, Miami, FL 33199 USA
[3] Marquette Univ, Milwaukee, WI 53233 USA
[4] Tuskegee Univ, Tuskegee, AL 36088 USA
[5] Worcester Polytech Inst, Worcester, MA 01609 USA
来源
2019 IEEE 43RD ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1 | 2019年
基金
美国国家科学基金会;
关键词
Android; Secure software development; Static analysis; Tainted data flow; SQL Injection;
D O I
10.1109/COMPSAC.2019.00087
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
While the number of mobile applications are rapidly growing, these applications are often coming with numerous security flaws due to the lack of appropriate coding practices. Security issues must be addressed earlier in the development lifecycle rather than fixing them after the attacks because the damage might already be extensive. Early elimination of possible security vulnerabilities will help us increase the security of our software and mitigate or reduce the potential damages through data losses or service disruptions caused by malicious attacks. However, many software developers lack necessary security knowledge and skills required at the development stage, and Secure Mobile Software Development (SMSD) is not yet well represented in academia and industry. In this paper, we present a static analysis-based security analysis approach through design and implementation of a plugin for Android Development Studio, namely DroidPatrol. The proposed plugins can support developers by providing list of potential vulnerabilities early.
引用
收藏
页码:565 / 569
页数:5
相关论文
共 50 条
  • [31] Towards a delegation-type secure software development method
    Mihelic, Anze
    Hovelja, Tomaz
    Vrhovec, Simon L. R.
    THIRD CENTRAL EUROPEAN CYBERSECURITY CONFERENCE (CECC 2019), 2019,
  • [32] Security Threat and Vulnerability Assessment and Measurement in Secure Software Development
    Humayun, Mamoona
    Jhanjhi, N. Z.
    Almufareh, Maram Fahhad
    Khalil, Muhammad Ibrahim
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 71 (03): : 5039 - 5059
  • [33] ABET Cybersecurity Continual Course Improvements for Secure Software Development
    Schmeelk, Suzanna E.
    Dragos, Denise M.
    DeBello, Joan E.
    2021 IEEE FRONTIERS IN EDUCATION CONFERENCE (FIE 2021), 2021,
  • [34] Automated security testing of Android applications for secure mobile development
    Palma, Francisco
    Realista, Nuno
    Serrao, Carlos
    Nunes, Luis
    Oliveira, Joao
    Almeida, Ana
    2020 IEEE 13TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION WORKSHOPS (ICSTW), 2020, : 222 - 231
  • [35] Verifying Data Secure Flow in AUTOSAR Models by Static Analysis
    Bernardeschi, Cinzia
    Di Natale, Marco
    Dini, Gianluca
    Palmieri, Maurizio
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 704 - 713
  • [36] Software Engineering: Challenges and their Solution in Mobile App Development
    Kousar, Naila
    Sheraz, Muhammad
    Malik, Arshad
    Sarwar, Aramghan
    Mohy-ud-din, Burhan
    Shahid, Ayesha
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2018, 9 (01) : 200 - 203
  • [37] Evaluating Static Analysis Defect Warnings On Production Software
    Ayewah, Nathaniel
    Pugh, William
    Morgenthaler, J. David
    Penix, John
    Zhou, YuQian
    PASTE'07 PROCEEDINGS OF THE 2007 ACM SIGPLAN- SIGSOFT WORKSHOP ON PROGRAM ANALYSIS FOR SOFTWARE TOOLS & ENGINEERING, 2007, : 1 - +
  • [38] Finding Cuts in Static Analysis Graphs to Debloat Software
    Blumschein, Christoph
    Niephaus, Fabio
    Stancu, Codrut
    Wimmer, Christian
    Lincke, Jens
    Hirschfeld, Robert
    PROCEEDINGS OF THE 33RD ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, ISSTA 2024, 2024, : 603 - 614
  • [39] Static Analysis of Lyee Requirements for Legacy System Software
    Fujita, Hamido
    Mejri, Mohameed
    IPSI BGD TRANSACTIONS ON INTERNET RESEARCH, 2005, 1 (01): : 3 - 10
  • [40] A Scheme of Feasibility with Static Analysis in Software Testing Environment
    Lu, ManSha
    ADVANCES IN MULTIMEDIA, SOFTWARE ENGINEERING AND COMPUTING, VOL 1, 2011, 128 : 69 - 73