DroidXP: A Benchmark for Supporting the Research on Mining Android Sandboxes

Francisco Handrick da Costa, I. Medeiros, P. Costa, T. Menezes, Marcos Vinícius, R. Bonifácio, E. Canedo
{"title":"DroidXP: A Benchmark for Supporting the Research on Mining Android Sandboxes","authors":"Francisco Handrick da Costa, I. Medeiros, P. Costa, T. Menezes, Marcos Vinícius, R. Bonifácio, E. Canedo","doi":"10.1109/SCAM51674.2020.00021","DOIUrl":null,"url":null,"abstract":"Due to the popularization of Android and the full range of applications (apps) targeting this platform, many security issues have emerged, attracting researchers and practitioners’ attention. As such, many techniques for addressing security Android issues have emerged, including approaches for mining sandboxes using dynamic analysis tools (i.e., automated testing tools). Undoubtedly, the resulting sandboxes’ efficiency depends on the test case generation tools used in the mining procedures. Previous research studies have compared Android test case generation tools for this specific goal. However, it is difficult to increment the research in this field because reproducing these previous empirical studies is a challenging and time-consuming task. This difficulty occurs because it is necessary to integrate test generation tools that often require different and conflicting versions of the Android platform, programming languages (e.g., Python 2 and Python 3), and software libraries. To mitigate this issue, in this paper we present DroidXP, a software infrastructure that allows researchers (and tools developers) to integrate and compare test case generation tools for mining sandboxes. We evaluated DroidXP through a reproduction study of previous research work, though considering additional test case generation tools. Our experiment suggests that DroidXP simplifies the comparison of existing tools for mining sandboxes, and revealed that Sapienz outperforms the other test case generation tools—regardless of the Monkey tool had presented the highest code coverage in our study.","PeriodicalId":410351,"journal":{"name":"2020 IEEE 20th International Working Conference on Source Code Analysis and Manipulation (SCAM)","volume":"58 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE 20th International Working Conference on Source Code Analysis and Manipulation (SCAM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SCAM51674.2020.00021","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Due to the popularization of Android and the full range of applications (apps) targeting this platform, many security issues have emerged, attracting researchers and practitioners’ attention. As such, many techniques for addressing security Android issues have emerged, including approaches for mining sandboxes using dynamic analysis tools (i.e., automated testing tools). Undoubtedly, the resulting sandboxes’ efficiency depends on the test case generation tools used in the mining procedures. Previous research studies have compared Android test case generation tools for this specific goal. However, it is difficult to increment the research in this field because reproducing these previous empirical studies is a challenging and time-consuming task. This difficulty occurs because it is necessary to integrate test generation tools that often require different and conflicting versions of the Android platform, programming languages (e.g., Python 2 and Python 3), and software libraries. To mitigate this issue, in this paper we present DroidXP, a software infrastructure that allows researchers (and tools developers) to integrate and compare test case generation tools for mining sandboxes. We evaluated DroidXP through a reproduction study of previous research work, though considering additional test case generation tools. Our experiment suggests that DroidXP simplifies the comparison of existing tools for mining sandboxes, and revealed that Sapienz outperforms the other test case generation tools—regardless of the Monkey tool had presented the highest code coverage in our study.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
DroidXP:支持挖掘Android沙盒研究的基准
由于Android的普及以及针对该平台的各种应用程序(app),出现了许多安全问题,引起了研究人员和从业者的关注。因此,许多解决Android安全问题的技术已经出现,包括使用动态分析工具(即自动化测试工具)挖掘沙箱的方法。毫无疑问,产生的沙盒的效率取决于在挖掘过程中使用的测试用例生成工具。之前的研究已经比较了Android测试用例生成工具来实现这一特定目标。然而,由于复制这些先前的实证研究是一项具有挑战性和耗时的任务,因此很难增加这一领域的研究。出现这种困难是因为有必要集成测试生成工具,这些工具通常需要不同且冲突的Android平台版本、编程语言(例如,Python 2和Python 3)和软件库。为了缓解这个问题,在本文中,我们提出了DroidXP,这是一个软件基础设施,允许研究人员(和工具开发人员)集成和比较挖掘沙箱的测试用例生成工具。我们通过对先前研究工作的再现研究来评估DroidXP,尽管考虑了额外的测试用例生成工具。我们的实验表明,DroidXP简化了对挖掘沙箱的现有工具的比较,并揭示了Sapienz优于其他测试用例生成工具——不管Monkey工具在我们的研究中呈现了最高的代码覆盖率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Failure of One, Fall of Many: An Exploratory Study of Software Features for Defect Prediction MUTAMA: An Automated Multi-label Tagging Approach for Software Libraries on Maven DroidXP: A Benchmark for Supporting the Research on Mining Android Sandboxes Techniques for Efficient Automated Elimination of False Positives Towards Detecting Inconsistent Comments in Java Source Code Automatically
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1