An Empirical Study on Android-related Vulnerabilities

被引:46
|
作者
Linares-Vasquez, Mario [1 ]
Bavota, Gabriele [2 ]
Escobar-Velasquez, Camilo [1 ]
机构
[1] Univ Los Andes, Syst & Comp Engn Dept, Bogota, Colombia
[2] Univ Svizzera Italiana, Fac Informat, Lugano, Switzerland
来源
2017 IEEE/ACM 14TH INTERNATIONAL CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR 2017) | 2017年
关键词
D O I
10.1109/MSR.2017.60
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Mobile devices are used more and more in everyday life. They are our cameras, wallets, and keys. Basically, they embed most of our private information in our pocket. For this and other reasons, mobile devices, and in particular the software that runs on them, are considered first-class citizens in the software-vulnerabilities landscape. Several studies investigated the software-vulnerabilities phenomenon in the context of mobile apps and, more in general, mobile devices. Most of these studies focused on vulnerabilities that could affect mobile apps, while just few investigated vulnerabilities affecting the underlying platform on which mobile apps run: the Operating System (OS). Also, these studies have been run on a very limited set of vulnerabilities. In this paper we present the largest study at date investigating Android-related vulnerabilities, with a specific focus on the ones affecting the Android OS. In particular, we (i) define a detailed taxonomy of the types of Android-related vulnerability; (ii) investigate the layers and subsystems from the Android OS affected by vulnerabilities; and (iii) study the survivability of vulnerabilities (i.e., the number of days between the vulnerability introduction and its fixing). Our findings could help OS and apps developers in focusing their verification & validation activities, and researchers in building vulnerability detection tools tailored for the mobile world.
引用
收藏
页码:2 / 13
页数:12
相关论文
共 50 条
  • [31] An empirical study of software aging manifestations in Android
    Qiao, Yu
    Zheng, Zheng
    Qin, FangYun
    2016 IEEE 27TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW), 2016, : 84 - 90
  • [32] Empirical Results on the Study of Software Vulnerabilities (NIER Track)
    Wu, Yan
    Siy, Harvey
    Gandhi, Robin
    2011 33RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE), 2011, : 964 - 967
  • [33] An Empirical Study of SSL Usage in Android Apps
    Shin, Dongwan
    Sun, Jiangfeng
    2018 52ND ANNUAL IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2018, : 217 - 221
  • [34] A Survey of Security Vulnerabilities in Android Automotive Apps
    Moiz, Abdul
    Alalfi, Manar H.
    3RD INTERNATIONAL WORKSHOP ON ENGINEERING AND CYBERSECURITY OF CRITICAL SYSTEMS (ENCYCRIS 2022), 2022, : 17 - 24
  • [35] Detection of SQLite Database Vulnerabilities in Android Apps
    Jain, Vineeta
    Gaur, M. S.
    Laxmi, Vijay
    Mosbah, Mohamed
    INFORMATION SYSTEMS SECURITY, 2016, 10063 : 521 - 531
  • [36] Mitigating Remote Code Execution Vulnerabilities: A Study on Tomcat and Android Security Updates
    Bier, Stephen
    Fajardo, Brian
    Ezeadum, Obinna
    Guzman, German
    Sultana, Kazi Zakia
    Anu, Vaibhav
    2021 IEEE INTERNATIONAL IOT, ELECTRONICS AND MECHATRONICS CONFERENCE (IEMTRONICS), 2021, : 874 - 879
  • [37] VULHUNTER: TOWARD DISCOVERING VULNERABILITIES IN ANDROID APPLICATIONS
    Qian, Chenxiong
    Luo, Xiapu
    Le, Yu
    Gu, Guofei
    IEEE MICRO, 2015, 35 (01) : 44 - 53
  • [38] Static Detection of Filesystem Vulnerabilities in Android Systems
    Lee, Yu-Tsung
    Vijayakumar, Hayawardh
    Qian, Zhiyun
    Jaeger, Trent
    arXiv,
  • [39] How We Found These Vulnerabilities in Android Applications
    Ma, Bin
    INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2014, PT II, 2015, 153 : 399 - 406
  • [40] Messaging Attacks on Android: Vulnerabilities and Intrusion Detection
    Hamandi, Khodor
    Salman, Alaa
    Elhajj, Imad H.
    Chehab, Ali
    Kayssi, Ayman
    MOBILE INFORMATION SYSTEMS, 2015, 2015