引用本文:林高毅,崔展齐,陈翔,郑丽伟.状态转换图制导的ARP错误检测方法.软件学报,2025,36(2):469-487
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1144次   下载 3526 本文二维码信息
码上扫一扫!
分享到: 微信 更多
状态转换图制导的ARP错误检测方法
林高毅1, 崔展齐1, 陈翔2, 郑丽伟1
1.北京信息科技大学 计算机学院, 北京 100101;2.南通大学 信息科学技术学院, 江苏 南通 226019
摘要:
Android应用开发人员需要在保持应用频繁更新的同时快速检测出应用中Android运行时权限(Android runtime permission, ARP)错误. 现有的Android应用自动化测试工具通常未考虑ARP机制, 无法有效测试Android应用内的权限相关行为. 为帮助开发人员快速检测出应用中ARP错误, 提出状态转换图制导的Android应用运行时权限错误检测方法. 首先, 对被测应用APK文件进行权限误用分析, 插桩APK文件中可能导致ARP错误的API, 并对APK文件重新签名; 然后, 安装插桩后的APK文件, 动态探索应用以生成其状态转换图(state transition graph, STG); 最后, 使用STG制导自动化测试, 快速检测出应用中ARP错误. 基于所提出方法实现原型工具RPBDroid, 并与ARP错误动态检测工具SetDroid、PermDroid和传统自动化测试工具APE进行对比实验. 实验结果表明, RPBDroid成功检测出17个应用中的15个ARP错误, 比APE、SetDroid、PermDroid分别多14、12和14个. 此外, 相比于测试工具SetDroid、PermDroid和APE, RPBDroid检测ARP错误的平均用时分别减少86.42%、86.72%和86.70%.
关键词:  Android应用  Android运行时权限错误  权限误用  自动化测试工具  状态转换图
DOI:10.13328/j.cnki.jos.007142
分类号:TP311
基金项目:江苏省前沿引领技术基础研究专项(BK20202001); 北京信息科技大学“勤信人才”培育计划(QXTCP C201906)
State Transition Graph Guided Testing Approach for Detecting ARP Bugs
LIN Gao-Yi1, CUI Zhan-Qi1, CHEN Xiang2, ZHENG Li-Wei1
1.School of Computer Science, Beijing Information Science and Technology University, Beijing 100101, China;2.School of Information Science and Technology, Nantong University, Nantong 226019, China
Abstract:
While keeping frequent application updates, Android application developers need to detect Android runtime permission (ARP) bugs as quickly as possible. Android applications cannot effectively be tested for permission-related behaviors with automated testing tools since they are rarely designed for ARP bugs. This study proposes a state transition graph guided testing approach for detecting ARP bugs in Android applications. First, it analyzes the APK file of the application under test for permission misuse, instruments the APIs that may cause ARP bugs in the APK file, and re-signs the APK file. Then, it installs the APK file and dynamically explores the application to generate its state transition graph (STG). Finally, it detects ARP bugs quickly by automated testing with the guidance of STG. To evaluate the effectiveness of the approach, the study implements a prototype tool RPBDroid and conducts comparative experiments with the ARP bug detection tools SetDroid, PermDroid, and the automated testing tool APE. The experimental results show that RPBDroid successfully detects 15 ARP bugs out of 17 applications, which detects 14, 12, and 14 more ARP bugs than APE, SetDroid, and PermDroid respectively. In addition, RPBDroid reduces the average time required to detect ARP bugs by 86.42%, 86.72%, and 86.70% in comparison with SetDroid, PermDroid, and APE.
Key words:  Android application  Android runtime permission (ARP) bug  permission misuse  automated testing tool  state transition graph (STG)

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: