TY - GEN
T1 - Towards black box testing of android apps
AU - Zhauniarovich, Y.
AU - Philippov, A.
AU - Gadyatskaya, O.
AU - Crispo, B.
AU - Massacci, F.
PY - 2015/10/16
Y1 - 2015/10/16
N2 - © 2015 IEEE.Many state-of-art mobile application testing frameworks (e.g., Dynodroid, Evo Droid) enjoy Emma or other code coverage libraries to measure the coverage achieved. The underlying assumption for these frameworks is availability of the app source code. Yet, application markets and security researchers face the need to test third-party mobile applications in the absence of the source code. There exists a number of frameworks both for manual and automated test generation that address this challenge. However, these frameworks often do not provide any statistics on the code coverage achieved, or provide coarse-grained ones like a number of activities or methods covered. At the same time, given two test reports generated by different frameworks, there is no way to understand which one achieved better coverage if the reported metrics were different (or no coverage results were provided). To address these issues we designed a framework called BBox Tester that is able to generate code coverage reports and produce uniform coverage metrics in testing without the source code. Security researchers can automatically execute applications exploiting current state-of-art tools, and use the results of our framework to assess if the security-critical code was covered by the tests. In this paper we report on design and implementation of BBox Tester and assess its efficiency and effectiveness.
AB - © 2015 IEEE.Many state-of-art mobile application testing frameworks (e.g., Dynodroid, Evo Droid) enjoy Emma or other code coverage libraries to measure the coverage achieved. The underlying assumption for these frameworks is availability of the app source code. Yet, application markets and security researchers face the need to test third-party mobile applications in the absence of the source code. There exists a number of frameworks both for manual and automated test generation that address this challenge. However, these frameworks often do not provide any statistics on the code coverage achieved, or provide coarse-grained ones like a number of activities or methods covered. At the same time, given two test reports generated by different frameworks, there is no way to understand which one achieved better coverage if the reported metrics were different (or no coverage results were provided). To address these issues we designed a framework called BBox Tester that is able to generate code coverage reports and produce uniform coverage metrics in testing without the source code. Security researchers can automatically execute applications exploiting current state-of-art tools, and use the results of our framework to assess if the security-critical code was covered by the tests. In this paper we report on design and implementation of BBox Tester and assess its efficiency and effectiveness.
U2 - 10.1109/ARES.2015.70
DO - 10.1109/ARES.2015.70
M3 - Conference contribution
SN - 9781467365901
T3 - Proceedings - 10th International Conference on Availability, Reliability and Security, ARES 2015
SP - 501
EP - 510
BT - Proceedings - 10th International Conference on Availability, Reliability and Security, ARES 2015
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 10th International Conference on Availability, Reliability and Security, ARES 2015
Y2 - 24 August 2015 through 27 August 2015
ER -