透過您的圖書館登入
IP:3.144.154.208
  • 學位論文

CRAXDroid: Android 下的自動化攻擊產生系統

CRAXDroid: Crash Analysis for Automatic Exploit Generation on Android System

指導教授 : 黃世昆 陳穎平

摘要


"The number of mobile-connected devices will exceed the world’s population by 2014.", said Cisco. People live on mobile devices nowadays literally, and the situation is still getting worse ever since company starts to embed smart devices into accessories, for example, glasses, watches, etc. Making life better is wonderful, while losing privacy is bad. The prevalence of modern smart devices, such as smart phones and tablets, are owed to enriched third-party applications, or so-called apps. However, most mobile device users have no idea how their privacy data are potentially exposed by using or just installing apps that are badly designed. These apps may not be designed with malicious intention, but may contain software design flaws, or bugs, which could be exploited and further take over control of the device. From the moment on, invaders may pry into victims' life without its knowing. Besides privacy leakage, invaders may take victims' as a gateway or even a member of a botnet to further attack other victims. As a result, software quality becomes a critical issue on mobile devices. CRAXDroid is built as a platform aiming at vulnerability discovering and exploiting of Android apps.

並列摘要


"The number of mobile-connected devices will exceed the world’s population by 2014.", said Cisco. People live on mobile devices nowadays literally, and the situation is still getting worse ever since company starts to embed smart devices into accessories, for example, glasses, watches, etc. Making life better is wonderful, while losing privacy is bad. The prevalence of modern smart devices, such as smart phones and tablets, are owed to enriched third-party applications, or so-called apps. However, most mobile device users have no idea how their privacy data are potentially exposed by using or just installing apps that are badly designed. These apps may not be designed with malicious intention, but may contain software design flaws, or bugs, which could be exploited and further take over control of the device. From the moment on, invaders may pry into victims' life without its knowing. Besides privacy leakage, invaders may take victims' as a gateway or even a member of a botnet to further attack other victims. As a result, software quality becomes a critical issue on mobile devices. CRAXDroid is built as a platform aiming at vulnerability discovering and exploiting of Android apps.

並列關鍵字

Android Apps Exploit Symbolic Execution Software Quality

參考文獻


[1] Vitaly Chipounov, Volodymyr Kuznetsov, and George Candea. "S2E: A platform for in-
[7] Rafael Fedler, Marcel Kulicke, and Julian Schüe. "Native code execution control for
[12] Sebastian Höbarth and Rene Mayrhofer. "A framework for on-device privilege escala-
vivo multi-path analysis of soware systems". In: ACM SIGARCH Computer Architecture
News 39.1 (2011), pp. 265­278.

被引用紀錄


簡玉惠(2017)。休閒農業產業經營績效模式之建構與分析〔博士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu201700407
李勇煥(2008)。基於及時通訊系統之UPnP家庭網路閘道〔碩士論文,大同大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0081-0607200917243524
吳駿榮(2013)。門市人員銷售行為對智慧型手機品牌排名的影響〔碩士論文,朝陽科技大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0078-2712201314043142

延伸閱讀