Information Technology and Open Source: Applications for Education, Innovation, and Sustainability - SEFM 2012 Satellite Events, InSuEdu, MoKMaSD, and OpenCert Thessaloniki, Greece, October 1-2, 2012 Revised Selected Papers

Information Technology and Open Source: Applications for Education, Innovation, and Sustainability - SEFM 2012 Satellite Events, InSuEdu, MoKMaSD, and OpenCert Thessaloniki, Greece, October 1-2, 2012 Revised Selected Papers
复制标题

信息技术和开源:教育、创新和可持续发展的应用 - SEFM 2012 卫星活动、InSuEdu、MoKMaSD 和 OpenCert 塞萨洛尼基,希腊,2012 年 10 月 1-2 日修订的精选论文

DOI:
10.1007/978-3-642-54338-8_24
复制
发表时间:
2014
期刊:
--
影响因子:
--
通讯作者:
Kalutarage H
Kalutarage H
中科院分区:
--
文献类型:
--
作者:
Kalutarage H

文献摘要

相似文献

过去十年见证了软件应用程序移动平台的出现。这一领域显著增长的一个重要因素是Android的发展以及共享开源和免费软件的移动应用开发者社区。虽然Android的重点是开放性和用户控制,但这也带来了验证和保护移动应用程序的挑战。到目前为止,用于测试移动应用程序功能和非功能属性的专用工具和技术的开发还很有限。鉴于Android在其短暂的历史中频繁的版本更新(十年内超过十次),这种努力变得更加困难。另一方面,随着提供银行、导航和身份管理等重要服务的应用程序的出现,对移动应用程序更好的安全性和保障的需求也越来越大。本文试图集中当前的概念和实践测试的移动应用程序。我们为移动应用程序的漏洞评估和权限映射提供了一个结构化的检查表方法,并以一组可用的工具为基础,最终为移动应用程序的认证框架做出贡献。拟议的认证过程结合了多种来源,并以自动化为重点。
The last decade has seen the emergence of mobile platform for software applications. An important factor in the remarkable growth in this area is the development of Android and a community of mobile application developers sharing open sourced and free software. While the emphasis for Android has been openness and user control, this brings with it challenges of validating and securing mobile apps. Development of dedicated tools and techniques to test mobile apps for functional and nonfunctional properties has been limited so far. Such an effort is made more difficult given frequent version updates for Android in its short history (over ten in ten years). The need for better security and assurance for mobile apps, on the other hand, is ever so more as apps providing important services such as banking, navigation, and identity management emerge. This paper attempts to converge on current concepts and practices of testing mobile apps. We provide a structured checklist approach to vulnerability assessment and permission mapping of mobile apps, which is underpinned by a set of available tools, and ultimately contribute to a framework for certification of mobile apps. The proposed certification process combines diverse sources and has a focus on automation.