3.8 Proceedings Paper

Chizpurfle: A Gray-Box Android Fuzzer for Vendor Service Customizations

出版社

IEEE
DOI: 10.1109/ISSRE.2017.16

关键词

Android OS; robustness testing; fuzzing; vendor customizations

资金

  1. UniNA
  2. Compagnia di San Paolo in the frame of Programme STAR (project FIDASTE)
  3. COSMIC project (DIETI department)

向作者/读者索取更多资源

Android has become the most popular mobile OS, as it enables device manufacturers to introduce customizations to compete with value-added services. However, customizations make the OS less dependable and secure, since they can introduce software flaws. Such flaws can be found by using fuzzing, a popular testing technique among security researchers. This paper presents Chizpurfle, a novel gray-box fuzzing tool for vendor-specific Android services. Testing these services is challenging for existing tools, since vendors do not provide source code and the services cannot be run on a device emulator. Chizpurfle has been designed to run on an unmodified Android OS on an actual device. The tool automatically discovers, fuzzes, and profiles proprietary services. This work evaluates the applicability and performance of Chizpurfle on the Samsung Galaxy S6 Edge, and discusses software bugs found in privileged vendor services.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据