3.8 Proceedings Paper

An Android Vulnerability Detection System

Journal

NETWORK AND SYSTEM SECURITY
Volume 10394, Issue -, Pages 169-183

Publisher

SPRINGER INTERNATIONAL PUBLISHING AG
DOI: 10.1007/978-3-319-64701-2_13

Keywords

Vulnerability; Android linux kernel; Imitating attack

Funding

  1. National Natural Science Foundation of China [61602361]

Ask authors/readers for more resources

Android system versions update and iterate frequently with severe fragmentation. The distribution of the various Android versions' market share is scattered, making system-level vulnerabilities' risk extensive and serious. For the limitations of the present research, we design and implement a new comprehensive system-level vulnerability detection system VScanner. For the first time VScanner is based on Lua script engine as the core. It gives priority to dynamic detection by exploiting, and static detection by feature matching is complementary. Vulnerability trigger is developed by the form of plugins, and it bases on vulnerability taxonomy by POCAS, which shows good scalability. For system-level vulnerabilities, we have implemented 18 plugins, which all are system-level vulnerabilities in high risk. By experimental evaluation, VScanner has high efficiency, low false alarm rate, and good effects on vulnerability detection.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

3.8
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available