Towards supporting software assurance assessments by detecting security patterns
Towards supporting software assurance assessments by detecting security patterns
复制标题
通过检测安全模式来支持软件保障评估
DOI:
10.1007/s11219-019-09492-z
复制
发表时间:
2020
影响因子:
1.9
通讯作者:
Karsten
中科院分区:
文献类型:
--
作者:
Michaela ;Karsten
Today, many tools exist that attempt to find possible vulnerabilities in Android applications, e.g., FlowDroid, Fortify, or AppScan. However, all these tools aim to detect vulnerabilities or (sometimes) tainted flows and present the reviewer detected possible issues of an analyzed Android application. None of these tools supports the identification of implemented security features in code, although this aspect is also relevant to developers as well as reviewers. To address this open problem, we present a program comprehension approach based on connected object process graphs (COPGs) containing interacting objects described by security patterns in this paper. The feasibility of our approach is evaluated qualitatively with 25 security-critical Android applications from Google Play with almost 7 million lines of code. We currently support 17 security pattern variants with about 199 correctly detected pattern instances in the apps. We also define a benchmark of non-trivial, security-critical Android apps, which can also be used for other security analysis tasks based on the static analysis framework Soot. With this benchmark, our analysis yields a precision of 99% and a recall of 80%. Finally, we discussed our approach and the developed tool with six software security experts from the SAFECode organization to obtain additional feedback.
登录
查看更多内容
影响因子:
3.5
作者:
T. Eisenbarth;R. Koschke;G. Vogel
通讯作者:
G. Vogel
DOI:
--
发表时间:
2005
期刊:
Conference on Object-Oriented Programming Systems, Languages, and Applications
影响因子:
--
作者:
M. Hafiz
通讯作者:
M. Hafiz
DOI:
--
发表时间:
2014
期刊:
Information Security Solutions Europe
影响因子:
--
作者:
Stacy Simpson
通讯作者:
Stacy Simpson
DOI:
--
发表时间:
2007
期刊:
影响因子:
--
作者:
M. VanHilst;E. Fernández
通讯作者:
E. Fernández
DOI:
--
发表时间:
2017
期刊:
International Conference on Software Security and Assurance
影响因子:
--
作者:
A. Alvi;Mohammad Zulkernine
通讯作者:
Mohammad Zulkernine