דילוג לניווט ראשי דילוג לחיפוש דילוג לתוכן הראשי

ApkFuzz: Search-Based Fuzzing for Android APK Vulnerability Discovery

פרסום מחקרי: פרק בספר / בדוח / בכנספרסום בספר כנסביקורת עמיתים

תקציר

While most work focuses on executable code, AndroidManifest.xml, serves as the primary entry point for application metadata and permission logic. Yet, it is often overlooked, making it a high-trust, low-scrutiny attack surface. We present ApkFuzz, an AFL-based fuzzer with bit-level mutations targeting the encoded region of AndroidManifest.xml in the APK file. We have identified 9 issues that cause crashes and enable Denial-of-Service (DoS) attacks in core tools, including Google’s apksigner and the widely used research tool DroidBot.

שפה מקוריתאנגלית
כותר פרסום המארחSearch-Based Software Engineering - 18th International Symposium, SSBSE 2026, Proceedings
עורכיםWesley K.G. Assunção, Mijung Kim, Ali Ouni
מוציא לאורSpringer Science and Business Media Deutschland GmbH
עמודים135-141
מספר עמודים7
מסת"ב (מודפס)9783032306982
מזהי עצם דיגיטלי (DOIs)
סטטוס פרסוםפורסם - 2027
אירוע18th International Symposium on Search-Based Software Engineering, SSBSE 2026 - Montreal, קנדה
משך הזמן: 5 יולי 20266 יולי 2026

סדרות פרסומים

שםLecture Notes in Computer Science
כרך16699 LNCS
ISSN (מודפס)0302-9743
ISSN (אלקטרוני)1611-3349

כנס

כנס18th International Symposium on Search-Based Software Engineering, SSBSE 2026
מדינה/אזורקנדה
עירMontreal
תקופה5/07/266/07/26

טביעת אצבע

להלן מוצגים תחומי המחקר של הפרסום 'ApkFuzz: Search-Based Fuzzing for Android APK Vulnerability Discovery'. יחד הם יוצרים טביעת אצבע ייחודית.

פורמט ציטוט ביבליוגרפי