APPregator: A Large-Scale Platform for Mobile Security Analysis

被引:0
|
作者
Verderame, Luca [1 ]
Caputo, Davide [1 ]
Romdhana, Andrea [1 ,2 ]
Merlo, Alessio [1 ]
机构
[1] Univ Genoa, DIBRIS, Genoa, Italy
[2] FBK ICT, Secur & Trust Unit, Trento, Italy
来源
基金
欧盟地平线“2020”;
关键词
App analysis; Static and dynamic analysis; Security and privacy;
D O I
10.1007/978-3-030-64881-7_5
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The Google Play Store currently includes up to 2.8M apps. Nonetheless, it is rather straightforward for a user to quickly retrieve the app that matches her tastes, as Google provides a reliable search engine. However, it is likewise almost impossible to select apps according to a security footprint (e.g., all apps that enforce SSL pinning) To overcome this limitation, this paper presents APPregator, a platform which allows security analysts to i) download apps from multiple app stores, ii) perform automated security analysis (both static and dynamic), and iii) aggregate the results according to user-defined security constraints (e.g., vulnerability patterns). The empirical assessment of APPregator on a set of 200.000 apps taken from the Google Play Store and Aptoide suggests that the current implementation grants a good level of performance and reliability. APPregator will be made freely available to the research community by the end of 2020.
引用
收藏
页码:73 / 88
页数:16
相关论文
共 50 条
  • [1] Building a Big Data Platform for Large-scale Security Data Analysis
    Lee, Jong-Hoon
    Kim, Young Soo
    Kim, Jong Hyun
    Kim, Ik Kyun
    Han, Ki-Jun
    [J]. 2017 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2017, : 976 - 980
  • [2] An Extensible Pervasive Platform for Large-scale Anticipatory Mobile Computing
    Meurisch, Christian
    Jeutter, Bennet
    Schmidt, Wladimir
    Guendling, Nickolas
    Schmidt, Benedikt
    Herrlich, Fabian
    Muehlhaeuser, Max
    [J]. 2017 IEEE 41ST ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2017, : 459 - 464
  • [3] A Cross-Platform Consumer Behavior Analysis of Large-Scale Mobile Shopping Data
    Huang, Hong
    Zhao, Bo
    Zhao, Hao
    Zhuang, Zhou
    Wang, Zhenxuan
    Yao, Xiaoming
    Wang, Xinggang
    Jin, Hai
    Fu, Xiaoming
    [J]. WEB CONFERENCE 2018: PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE (WWW2018), 2018, : 1785 - 1794
  • [4] A security scheme for mobile agent platforms in large-scale systems
    Wangham, MS
    Fraga, JD
    Obelheiro, RR
    [J]. COMMUNICATIONS AND MULTIMEDIA SECURITY, 2003, 2828 : 104 - 116
  • [5] Large-Scale Analysis of the Security of Embedded Firmwares
    Costin, Andrei
    Zaddach, Jonas
    Francillon, Aurelien
    Balzarotti, Davide
    [J]. PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, 2014, : 95 - 110
  • [6] Large-Scale Mobile Traffic Analysis: A Survey
    Naboulsi, Diala
    Fiore, Marco
    Ribot, Stephane
    Stanica, Razvan
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2016, 18 (01): : 124 - 161
  • [7] Galaxy: A platform for interactive large-scale genome analysis
    Giardine, B
    Riemer, C
    Hardison, RC
    Burhans, R
    Elnitski, L
    Shah, P
    Zhang, Y
    Blankenberg, D
    Albert, I
    Taylor, J
    Miller, W
    Kent, WJ
    Nekrutenko, A
    [J]. GENOME RESEARCH, 2005, 15 (10) : 1451 - 1455
  • [8] Large-scale simulation platform
    Institute of Cybernetics, Tallinn Technical University, Akadeemia tee 21, 12618 Tallinn, Estonia
    [J]. WSEAS Trans. Comput, 2007, 1 (65-71):
  • [9] Implementation of a Massively Parallel Dynamic Security Assessment Platform for Large-Scale Grids
    Konstantelos, Ioannis
    Jamgotchian, Geoffroy
    Tindemans, Simon
    Duchesne, Philippe
    Cole, Stijn
    Merckx, Christian
    Strbac, Goran
    Panciatici, Partick
    [J]. 2018 IEEE POWER & ENERGY SOCIETY GENERAL MEETING (PESGM), 2018,
  • [10] Implementation of a Massively Parallel Dynamic Security Assessment Platform for Large-Scale Grids
    Konstantelos, Ioannis
    Jamgotchian, Geoffroy
    Tindemans, Simon H.
    Duchesne, Philippe
    Cole, Stijn
    Merckx, Christian
    Strbac, Goran
    Panciatici, Patrick
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2017, 8 (03) : 1417 - 1426