Android devices are shipped in several flavors by more than 100 manufacturer partners, which extend the Android “vanilla” OS with new system services, and modify the existing ones. These proprietary extensions expose Android devices to reliability and security issues. In this paper, we propose a coverage-guided fuzzing platform (Chizpurfle) based on evolutionary algorithms to test proprietary Android system services. A key feature of this platform is the ability to profile coverage on the actual, unmodified Android device, by taking advantage of dynamic binary re-writing techniques. We applied this solution on three high-end commercial Android smartphones. The results confirmed that evolutionary fuzzing is able to test Android OS system services more efficiently than blind fuzzing. Furthermore, we evaluate the impact of different choices for the fitness function and selection algorithm

Evolutionary Fuzzing of Android OS Vendor System Services / Cotroneo, D.; Iannillo, A. K.; Natella, R.. - In: EMPIRICAL SOFTWARE ENGINEERING. - ISSN 1382-3256. - 24:6(2019), pp. 3630-3658. [10.1007/s10664-019-09725-6]

Evolutionary Fuzzing of Android OS Vendor System Services

Cotroneo D.;Iannillo A. K.;Natella R.
2019

Abstract

Android devices are shipped in several flavors by more than 100 manufacturer partners, which extend the Android “vanilla” OS with new system services, and modify the existing ones. These proprietary extensions expose Android devices to reliability and security issues. In this paper, we propose a coverage-guided fuzzing platform (Chizpurfle) based on evolutionary algorithms to test proprietary Android system services. A key feature of this platform is the ability to profile coverage on the actual, unmodified Android device, by taking advantage of dynamic binary re-writing techniques. We applied this solution on three high-end commercial Android smartphones. The results confirmed that evolutionary fuzzing is able to test Android OS system services more efficiently than blind fuzzing. Furthermore, we evaluate the impact of different choices for the fitness function and selection algorithm
2019
Evolutionary Fuzzing of Android OS Vendor System Services / Cotroneo, D.; Iannillo, A. K.; Natella, R.. - In: EMPIRICAL SOFTWARE ENGINEERING. - ISSN 1382-3256. - 24:6(2019), pp. 3630-3658. [10.1007/s10664-019-09725-6]
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11588/766776
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 11
  • ???jsp.display-item.citation.isi??? 8
social impact