Secure Mobile Software Development with Vulnerability Detectors in Static Code Analysis

被引:0
作者
Meng, Xianyong [1 ]
Qian, Kai [1 ]
Lo, Dan [1 ]
Bhattacharya, Prabir [2 ]
Wu, Fan [3 ]
机构
[1] Kennesaw State Univ, Comp Sci Dept, Kennesaw, GA 30144 USA
[2] Morgan State Univ, Comp Sci Dept, Baltimore, MD 21239 USA
[3] Tuskegee Univ, Comp Sci Dept, Tuskegee, AL 36088 USA
来源
2018 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2018) | 2018年
基金
美国国家科学基金会;
关键词
Android vulnerability; secure software development; static analysis; FindSecurityBugs;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security threats to mobile application are growing explosively. Mobile app flaws and security defects could open doors for hackers to easily attack mobile apps. Secure software development must be addressed earlier in the development lifecycle rather than fixing the security holes after attacking. Early eliminating against possible security vulnerability will help us increase the security of our software, and militate the consequence of damages of data loss caused by potential malicious attacking. However, many software developer professionals lack the necessary security knowledge and skills at the development stage and Secure Mobile Software Development (SMSD) is not yet well represented in current computing curriculum. In this paper we present a static security analysis approach with open source FindSecurityBugs plugin for Android Studio IDE. We categorized the common mobile vulnerability for developers based on OWASP mobile security recommendations and developed detectors to meet the SMSD needs in industry and education.
引用
收藏
页数:4
相关论文
共 6 条
[1]  
Chi Hongmei, INFOSECCD 13 P 2013
[2]  
Goseva-Popstojanovaa Katerina, CAPABILITY STATIC CO
[3]  
Whitney Michael, 2017, J ED COMPUTING RES
[4]  
Whitney Michael, P 46 ACM TECHN S COM
[5]  
Yuan J, 2016, 14TH USENIX CONFERENCE ON FILE AND STORAGE TECHNOLOGIES (FAST '16), P1
[6]  
Zhu Jun, 2013, P SIGCSE 2013 44 TEC