Vulnebdroid: Automated Vulnerability Score Calculator for Android Applications

被引:0
|
作者
Gupta, Sugandha [1 ]
Kaushal, Rishabh [1 ]
机构
[1] Indira Gandhi Delhi Tech Univ Women, Dept Informat Technol, New Delhi, India
关键词
Android application; Vulnerability score; Malware; Obfuscation;
D O I
10.1007/978-981-10-2738-3_40
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Nowadays mobile phone users download lots of applications for various purposes like learning, entertainment, businesses, etc. For a naive user, it is very difficult to identify whether the permissions provided to the application at the time of installation are being used properly or not. There are tools available for the detection of android malware but many of them are not open source or give tricky results which are not easily understandable. Various online services like VirusTotal uses the updated anti viruses for computing the malware detection ratio. However, since most of these anti-viruses are based on signature based detection methodology, therefore, it detection can be circumvented by using obfuscation methods. In our work we have implemented VULNEBDROID, an automated light weight obfuscation-tolerant static tool for computing the vulnerability score and assessing the vulnerability level of android applications. To assess the vulnerability, this tool selects the features of the application, like dangerous permissions used; vulnerable functions which can be used in order to misuse the application and can exploit the Application Programming Interface (API) to access the resources. Using this assessment tool, we are able to detect 96% of malicious application as vulnerable either with high or medium degree of vulnerability.
引用
收藏
页码:461 / 471
页数:11
相关论文
共 50 条
  • [1] Androshield: Automated android applications vulnerability detection, a hybrid static and dynamic analysis approach
    Amin A.
    Eldessouki A.
    Magdy M.T.
    Abdeen N.
    Hindy H.
    Hegazy I.
    Information (Switzerland), 2019, 10 (10):
  • [2] AndroShield: Automated Android Applications Vulnerability Detection, a Hybrid Static and Dynamic Analysis Approach
    Amin, Amr
    Eldessouki, Amgad
    Magdy, Menna Tullah
    Abdeen, Nouran
    Hindy, Hanan
    Hegazy, Islam
    INFORMATION, 2019, 10 (10)
  • [3] AUSERA: Automated Security Vulnerability Detection for Android Apps
    Chen, Sen
    Zhang, Yuxin
    Fan, Lingling
    Li, Jiaming
    Liu, Yang
    PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,
  • [4] Examining the Privacy Vulnerability Level of Android Applications
    Kapitsaki, Georgia M.
    Ioannou, Modestos
    WEBIST: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, 2019, : 34 - 45
  • [5] Unintentional Bugs to Vulnerability Mapping in Android Applications
    Bajwa, Garima
    Fazeen, Mohamed
    Dantu, Ram
    Tanpure, Sonal
    2015 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2015, : 176 - 178
  • [6] Vulnerability Testing in Online Shopping Android Applications
    Tabassum, Faria
    Faisal, Abu Mohammad
    2017 IEEE REGION 10 HUMANITARIAN TECHNOLOGY CONFERENCE (R10-HTC), 2017, : 654 - 657
  • [7] CREATION AND VALIDATION OF AN EHR INTEGRATED AUTOMATED SOFA SCORE CALCULATOR
    Aakre, Christopher
    Kitson, Jaben
    Herasevich, Vitaly
    CRITICAL CARE MEDICINE, 2016, 44 (12)
  • [8] Assessment of Source Data Vulnerability to Reproduction in Android Applications
    Shafi, Muhammad
    Israr, Muhammad
    Khan, Muhammad Sohail
    Khattak, Muhammad Irfan
    Syed, Togeer Ali
    2017 9TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMMUNICATION NETWORKS (CICN), 2017, : 122 - 126
  • [9] Privacy Vulnerability Analysis for Android Applications A Practical Approach
    Argudo, Alejandro
    Lopez, Gabriel
    Sanchez, Franklin
    2017 FOURTH INTERNATIONAL CONFERENCE ON EDEMOCRACY & EGOVERNMENT (ICEDEG), 2017, : 256 - 260
  • [10] Automated GUI Testing for Android News Applications
    Chu, Edward T. -H.
    Lin, Jun-Yan
    2018 INTERNATIONAL SYMPOSIUM ON COMPUTER, CONSUMER AND CONTROL (IS3C 2018), 2018, : 14 - 17