Mining mobile app markets for prioritization of security assessment effort

Alireza Sadeghi, N. Esfahani, S. Malek
{"title":"Mining mobile app markets for prioritization of security assessment effort","authors":"Alireza Sadeghi, N. Esfahani, S. Malek","doi":"10.1145/3121264.3121265","DOIUrl":null,"url":null,"abstract":"Like any other software engineering activity, assessing the security of a software system entails prioritizing the resources and minimizing the risks. Techniques ranging from the manual inspection to automated static and dynamic analyses are commonly employed to identify security vulnerabilities prior to the release of the software. However, none of these techniques is perfect, as static analysis is prone to producing lots of false positives and negatives, while dynamic analysis and manual inspection are unwieldy, both in terms of required time and cost. This research aims to improve these techniques by mining relevant information from vulnerabilities found in the app markets. The approach relies on the fact that many modern software systems, in particular mobile software, are developed using rich application development frameworks (ADF), allowing us to raise the level of abstraction for detecting vulnerabilities and thereby making it possible to classify the types of vulnerabilities that are encountered in a given category of application. By coupling this type of information with severity of the vulnerabilities, we are able to improve the efficiency of static and dynamic analyses, and target the manual effort on the riskiest vulnerabilities.","PeriodicalId":179461,"journal":{"name":"Proceedings of the 2nd ACM SIGSOFT International Workshop on App Market Analytics","volume":"86 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-09-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2nd ACM SIGSOFT International Workshop on App Market Analytics","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3121264.3121265","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Like any other software engineering activity, assessing the security of a software system entails prioritizing the resources and minimizing the risks. Techniques ranging from the manual inspection to automated static and dynamic analyses are commonly employed to identify security vulnerabilities prior to the release of the software. However, none of these techniques is perfect, as static analysis is prone to producing lots of false positives and negatives, while dynamic analysis and manual inspection are unwieldy, both in terms of required time and cost. This research aims to improve these techniques by mining relevant information from vulnerabilities found in the app markets. The approach relies on the fact that many modern software systems, in particular mobile software, are developed using rich application development frameworks (ADF), allowing us to raise the level of abstraction for detecting vulnerabilities and thereby making it possible to classify the types of vulnerabilities that are encountered in a given category of application. By coupling this type of information with severity of the vulnerabilities, we are able to improve the efficiency of static and dynamic analyses, and target the manual effort on the riskiest vulnerabilities.
挖掘移动应用市场,确定安全评估工作的优先级
像任何其他软件工程活动一样,评估软件系统的安全性需要对资源进行优先排序并将风险最小化。从手工检查到自动静态和动态分析的技术通常用于在软件发布之前识别安全漏洞。然而,这些技术都不是完美的,因为静态分析容易产生大量的假阳性和阴性,而动态分析和人工检查在所需的时间和成本方面都是笨拙的。本研究旨在通过从应用程序市场中发现的漏洞中挖掘相关信息来改进这些技术。该方法依赖于这样一个事实,即许多现代软件系统,特别是移动软件,都是使用富应用程序开发框架(ADF)开发的,这允许我们提高检测漏洞的抽象级别,从而使对给定应用程序类别中遇到的漏洞类型进行分类成为可能。通过将这种类型的信息与漏洞的严重性相结合,我们能够提高静态和动态分析的效率,并将人工工作的目标放在最危险的漏洞上。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信