A Study on the Testing of Android Security Patches

A Study on the Testing of Android Security Patches
复制标题

DOI:
10.1109/cns56114.2022.9947240
复制
发表时间:
2022-10
期刊:
2022 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Christopher Brant;Tuba Yavuz
Christopher Brant;Tuba Yavuz
中科院分区:
其他
文献类型:
--
作者:
Christopher Brant;Tuba Yavuz

文献摘要

相似文献

Android控制着全球大部分操作系统市场。Android Open Source Project(AOSP)是一个非常复杂的系统,包含应用程序、应用程序框架、中间件、定制的Linux内核和可信组件等多个层次。虽然安全性在每一层都实现了,但由于管理用户界面和权限,应用程序框架形成了重要的攻击面。Android的安全性已经发展了多年。应用程序框架中发现的安全缺陷导致Android权限重新设计。这一演变的一部分包括对每月Android安全公告中公开发布的漏洞的修复。在这项研究中,我们分析了过去6年内Android安全公告中列出的CVE。我们专注于Android应用程序框架,并调查了几个研究问题,涉及1)安全相关组件,2)安全补丁的测试信息的类型和数量,以及3)设计用于测试这些补丁的测试的充分性。我们的研究结果表明,Android安全测试实践可以通过设计安全公告更新特定的测试,并通过提高补丁文件的代码覆盖率来进一步改进。
Android controls the majority of the global OS market. Android Open Source Project (AOSP) is a very complex system with many layers including the apps, the Application Framework, the middle-ware, the customized Linux kernel, and the trusted components. Although security is implemented in every layer, the Application Framework forms an important of the attack surface due to managing the user interface and permissions. Android security has evolved over the years. The security flaws that have been found in the Application Framework led to a redesign of Android permissions. Part of this evolution includes fixes to the vulnerabilities that are publicly released in the monthly Android security bulletins. In this study, we analyze the CVEs listed in the Android security bulletin within the last 6 years. We focus on the Android application framework and investigate several research questions relating to 1) the security relevant components, 2) the type and amount of testing information for the security patches, and 3) the adequacy of the tests designed to test these patches. Our findings indicate that Android security testing practices can be further improved by designing security bulletin update specific tests, and by improving code coverage of patched files.