中文

与软件模块相关的移动应用漏洞研究

密码学与安全 2017-03-28 v3

摘要

本文报告了一项大规模研究,旨在理解移动应用(app)漏洞如何与软件库相关联。我们分析了免费和付费应用。研究付费应用非常有意义,因为它帮助我们理解应用开发/维护的差异如何影响与库相关的漏洞。我们分析了从官方Android市场收集的30k免费和付费应用。我们的广泛分析揭示,免费/付费应用约70%/50%的漏洞源于软件库,特别是第三方库。有些矛盾的是,我们发现更昂贵/更受欢迎的付费应用往往具有更多漏洞。这源于以下事实:更昂贵/更受欢迎的付费应用往往具有更多功能,即更多代码和库,从而增加了漏洞出现的概率。基于我们的发现,我们向移动应用分发生态系统的利益相关者提供了建议。

关键词

引用

@article{arxiv.1702.03112,
  title  = {A Study on the Vulnerabilities of Mobile Apps associated with Software Modules},
  author = {Takuya Watanabe and Mitsuaki Akiyama and Fumihiro Kanei and Eitaro Shioji and Yuta Takata and Bo Sun and Yuta Ishi and Toshiki Shibahara and Takeshi Yagi and Tatsuya Mori},
  journal= {arXiv preprint arXiv:1702.03112},
  year   = {2017}
}

备注

This is full version of the following paper: "Understanding the Origins of Mobile App Vulnerabilities: A Large-scale Measurement Study of Free and Paid Apps" Proceedings of IEEE/ACM 14th International Conference on Mining Software Repositories (MSR 2017), May 2017