SEBASTiAn: A static and extensible black-box application security testing tool for iOS and Android applications

Autor: Francesco Pagano, Andrea Romdhana, Davide Caputo, Luca Verderame, Alessio Merlo
Jazyk: angličtina
Rok vydání: 2023
Předmět:
Zdroj: SoftwareX, Vol 23, Iss , Pp 101448- (2023)
Druh dokumentu: article
ISSN: 2352-7110
DOI: 10.1016/j.softx.2023.101448
Popis: Despite decades of research, the automatic detection of vulnerabilities in mobile apps remains an open challenge. Among the possible solutions, SAST tools uncover source or compiled code security flaws without needing the app to be executed and tested in a controlled environment. However, SAST tools share several limitations, such as the detection of narrowed vulnerability classes, lack of updates, and limited resiliency to obfuscation techniques. This paper presents SEBASTiAn, a black-box automatic static analysis tool for security vetting Android and iOS apps. It relies on a modular approach to cope with new vulnerabilities.
Databáze: Directory of Open Access Journals