Reducing False Positives in Statically Detecting Mobile App and Platform Level
Reducing False Positives in Statically Detecting Mobile App and Platform Level
批准号:
549598-2020
负责人:
Nagappan, MeiyappanMN
金额:
$10.93万
依托单位:
依托单位国家:
加拿大
项目类别:
Alliance Grants
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Mobile apps on the Android platform are used by billions of people. One requirement is to provide a secure experience for them. One way to ensure security is by analyzing the source code of the apps and the platform they execute on for security issues. Analyzing one without the other can cause issues since both data and control flow back and forth between them. We are going to use a combination of mining software repositories, machine learning, program slicing, frequent itemset mining, and call graph analysis among many different static analysis approaches to narrow down the potential security issues. At the end of the static analysis phase, we will have identified the type of vulnerability and wherein the source code of either the app and/or the platform the vulnerability is present. At this point, we will use model-based testing to see if that line(s) of code can be executed with an appropriate input. With such testing, we will not only be able to reduce the number of false positives, but also provide the developers with an appropriate test case where the vulnerability could be exploited. The final outcome of the project is to provide developers with the tools to make the end-user experience more secure.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金