We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Ghera: A Repository of Android App Vulnerability Benchmarks

Abstract: Security of mobile apps affects the security of their users. This has fueled the development of techniques to automatically detect vulnerabilities in mobile apps and help developers secure their apps; specifically, in the context of Android platform due to openness and ubiquitousness of the platform. Despite a slew of research efforts in this space, there is no comprehensive repository of up-to-date and lean benchmarks that contain most of the known Android app vulnerabilities and, consequently, can be used to rigorously evaluate both existing and new vulnerability detection techniques and help developers learn about Android app vulnerabilities. In this paper, we describe Ghera, an open source repository of benchmarks that capture 25 known vulnerabilities in Android apps (as pairs of exploited/benign and exploiting/malicious apps). We also present desirable characteristics of vulnerability benchmarks and repositories that we uncovered while creating Ghera.
Comments: 10 pages. Accepted at PROMISE'17
Subjects: Cryptography and Security (cs.CR); Software Engineering (cs.SE)
ACM classes: K.6.m; H.3.7
DOI: 10.1145/3127005.3127010
Cite as: arXiv:1708.02380 [cs.CR]
  (or arXiv:1708.02380v1 [cs.CR] for this version)

Submission history

From: Venkatesh-Prasad Ranganath [view email]
[v1] Tue, 8 Aug 2017 06:29:02 GMT (40kb)

Link back to: arXiv, form interface, contact.