Universal method and universal system for performing safety testing on Android application programs
A technology for security testing and application programs, applied in the field of information security, can solve the problems of increasing the difficulty of program cracking and reverse engineering, program security loopholes and vulnerability testing, evaluation, discovery and utilization, etc. Small false negative rate, reduced false positive rate, accurate information leakage effect
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0038] like figure 1 As shown, this embodiment includes the following steps:
[0039] 1) Unpack and decompile the program to be tested: use reverse tools such as apktool or jeb to decompile the dex code and decode the manifest.xml configuration file of Android,
[0040] 2) For the code obtained by decompilation and the configuration file obtained by decoding, use the static analysis method to perform security detection in four aspects:
[0041] 2.1) Component exposure: scan the components in the manifest file, if the exported attribute is set to true, if exported is not set and has intent-filtered, if exported is not set, and the provider whose sdkversion is set to be less than or equal to 16, it means that the component is exposed.
[0042] 2.2) Misuse of cryptography: Define a set of cryptography usage standards, such as the IV of CBC encryption mode must be random, ECB encryption mode should not be used, etc., and find a series of encryption in Java by scanning the source ...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com