基于Drozer的Android应用安全检测方法

Lin Xiaopeng, Wang Ning, Xiao Fei, Qian Fengchen, Ma Simin
{"title":"基于Drozer的Android应用安全检测方法","authors":"Lin Xiaopeng, Wang Ning, Xiao Fei, Qian Fengchen, Ma Simin","doi":"10.1109/ICSGEA.2018.00050","DOIUrl":null,"url":null,"abstract":"Drozer is the interactive Android security testing framework developed by MWR Labs. According to this framework, the dynamic analysis can be executed the actual equipment, and agent can be installed in the equipment or the simulator, the user-input commands are send to the agent program of Android device from server, the tool is extended by modifying local Python files or installing modules, and then more sophisticated, in-depth attacks on Android components are launched. First of all, a Drozer based Android APP security detection scanning plug-in is designed. Secondly, the software is tested by using the attack mode, detecting whether there is SQL injection vulnerability, rejection vulnerability, data backup vulnerability. Finally, the interaction information between the detecting software and Drozer is utilized, and the authoritative software security test report is automatically generated by one key, which provides a new intelligent method for the detection of Android software vulnerability.","PeriodicalId":445324,"journal":{"name":"2018 International Conference on Smart Grid and Electrical Automation (ICSGEA)","volume":"13 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Safety Detection Method of Android App Based on Drozer\",\"authors\":\"Lin Xiaopeng, Wang Ning, Xiao Fei, Qian Fengchen, Ma Simin\",\"doi\":\"10.1109/ICSGEA.2018.00050\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Drozer is the interactive Android security testing framework developed by MWR Labs. According to this framework, the dynamic analysis can be executed the actual equipment, and agent can be installed in the equipment or the simulator, the user-input commands are send to the agent program of Android device from server, the tool is extended by modifying local Python files or installing modules, and then more sophisticated, in-depth attacks on Android components are launched. First of all, a Drozer based Android APP security detection scanning plug-in is designed. Secondly, the software is tested by using the attack mode, detecting whether there is SQL injection vulnerability, rejection vulnerability, data backup vulnerability. Finally, the interaction information between the detecting software and Drozer is utilized, and the authoritative software security test report is automatically generated by one key, which provides a new intelligent method for the detection of Android software vulnerability.\",\"PeriodicalId\":445324,\"journal\":{\"name\":\"2018 International Conference on Smart Grid and Electrical Automation (ICSGEA)\",\"volume\":\"13 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-06-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 International Conference on Smart Grid and Electrical Automation (ICSGEA)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICSGEA.2018.00050\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Conference on Smart Grid and Electrical Automation (ICSGEA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSGEA.2018.00050","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

Drozer是MWR实验室开发的交互式Android安全测试框架。根据该框架,动态分析可以在实际设备上执行,代理可以安装在设备或模拟器中,用户输入的命令从服务器发送到Android设备的代理程序,通过修改本地Python文件或安装模块对工具进行扩展,然后对Android组件进行更复杂、更深入的攻击。首先,设计了一个基于Drozer的Android APP安全检测扫描插件。其次,采用攻击模式对软件进行测试,检测是否存在SQL注入漏洞、拒绝漏洞、数据备份漏洞。最后,利用检测软件与Drozer之间的交互信息,一键自动生成权威软件安全测试报告,为Android软件漏洞检测提供了一种新的智能方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Safety Detection Method of Android App Based on Drozer
Drozer is the interactive Android security testing framework developed by MWR Labs. According to this framework, the dynamic analysis can be executed the actual equipment, and agent can be installed in the equipment or the simulator, the user-input commands are send to the agent program of Android device from server, the tool is extended by modifying local Python files or installing modules, and then more sophisticated, in-depth attacks on Android components are launched. First of all, a Drozer based Android APP security detection scanning plug-in is designed. Secondly, the software is tested by using the attack mode, detecting whether there is SQL injection vulnerability, rejection vulnerability, data backup vulnerability. Finally, the interaction information between the detecting software and Drozer is utilized, and the authoritative software security test report is automatically generated by one key, which provides a new intelligent method for the detection of Android software vulnerability.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信