An Empirical Study on Android-related Vulnerabilities

被引:46
|
作者
Linares-Vasquez, Mario [1 ]
Bavota, Gabriele [2 ]
Escobar-Velasquez, Camilo [1 ]
机构
[1] Univ Los Andes, Syst & Comp Engn Dept, Bogota, Colombia
[2] Univ Svizzera Italiana, Fac Informat, Lugano, Switzerland
来源
2017 IEEE/ACM 14TH INTERNATIONAL CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR 2017) | 2017年
关键词
D O I
10.1109/MSR.2017.60
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Mobile devices are used more and more in everyday life. They are our cameras, wallets, and keys. Basically, they embed most of our private information in our pocket. For this and other reasons, mobile devices, and in particular the software that runs on them, are considered first-class citizens in the software-vulnerabilities landscape. Several studies investigated the software-vulnerabilities phenomenon in the context of mobile apps and, more in general, mobile devices. Most of these studies focused on vulnerabilities that could affect mobile apps, while just few investigated vulnerabilities affecting the underlying platform on which mobile apps run: the Operating System (OS). Also, these studies have been run on a very limited set of vulnerabilities. In this paper we present the largest study at date investigating Android-related vulnerabilities, with a specific focus on the ones affecting the Android OS. In particular, we (i) define a detailed taxonomy of the types of Android-related vulnerability; (ii) investigate the layers and subsystems from the Android OS affected by vulnerabilities; and (iii) study the survivability of vulnerabilities (i.e., the number of days between the vulnerability introduction and its fixing). Our findings could help OS and apps developers in focusing their verification & validation activities, and researchers in building vulnerability detection tools tailored for the mobile world.
引用
收藏
页码:2 / 13
页数:12
相关论文
共 50 条
  • [21] The life and death of statically detected vulnerabilities: An empirical study
    Di Penta, Massimiliano
    Cerulo, Luigi
    Aversano, Lerina
    INFORMATION AND SOFTWARE TECHNOLOGY, 2009, 51 (10) : 1469 - 1484
  • [22] An Empirical Study of Functional Bugs in Android Apps
    Xiong, Yiheng
    Xu, Mengqian
    Su, Ting
    Sun, Jingling
    Wang, Jue
    Wen, He
    Pu, Geguang
    He, Jifeng
    Su, Zhendong
    PROCEEDINGS OF THE 32ND ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, ISSTA 2023, 2023, : 1319 - 1331
  • [23] Investigating the Android Apps' Success: An Empirical Study
    Guerrouj, Latifa
    Baysal, Olga
    2016 IEEE 24TH INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION (ICPC), 2016,
  • [24] An Empirical Study of UI Implementations in Android Applications
    Wan, Mian
    Abolhassani, Negarsadat
    Alotaibi, Ali
    Halfond, William G. J.
    2019 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME 2019), 2019, : 65 - 75
  • [25] Accessing Inaccessible Android APIs: An Empirical Study
    Li, Li
    Bissyande, Tegawende F.
    Le Traon, Yves
    Klein, Jacques
    32ND IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME 2016), 2016, : 411 - 422
  • [26] An empirical study of Android Wear user complaints
    Mujahid, Suhaib
    Sierra, Giancarlo
    Abdalkareem, Rabe
    Shihab, Emad
    Shang, Weiyi
    EMPIRICAL SOFTWARE ENGINEERING, 2018, 23 (06) : 3476 - 3502
  • [27] An empirical study of Android Wear user complaints
    Suhaib Mujahid
    Giancarlo Sierra
    Rabe Abdalkareem
    Emad Shihab
    Weiyi Shang
    Empirical Software Engineering, 2018, 23 : 3476 - 3502
  • [28] An Empirical Study of Flaky Tests in Android Apps
    Chandani, Swapna
    Sreshtha, Chandani
    Meng, Na
    PROCEEDINGS 2018 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME), 2018, : 534 - 538
  • [29] An Empirical Study of the Energy Consumption of Android Applications
    Li, Ding
    Hao, Shuai
    Gui, Jiaping
    Halfond, William G. J.
    2014 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME), 2014, : 121 - 130
  • [30] An Empirical Study of Insecure Communication in Android Apps
    Zhang, Yue-heng
    Shu, Jun-liang
    Li, Juan-ru
    Wang, Qing
    Gu, Da-wu
    INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATION AND NETWORK ENGINEERING (WCNE 2016), 2016,