The Experts below are selected from a list of 1608 Experts worldwide ranked by ideXlab platform
Cristina Nita-rotaru - One of the best experts on this subject based on the ideXlab platform.
-
Chizpurfle: A Gray-Box Android Fuzzer for Vendor Service Customizations
2017 IEEE 28th International Symposium on Software Reliability Engineering (ISSRE), 2017Co-Authors: Antonio Ken Iannillo, Roberto Natella, Domenico Cotroneo, Cristina Nita-rotaruAbstract:Android has become the most popular mobile OS, as it enables Device manufacturers to introduce customizations to compete with value-added services. However, customizations make the OS less dependable and secure, since they can introduce software flaws. Such flaws can be found by using fuzzing, a popular testing technique among security researchers.This paper presents Chizpurfle, a novel "gray-box" fuzzing tool for vendor-specific Android services. Testing these services is challenging for existing tools, since vendors do not provide source code and the services cannot be run on a Device Emulator. Chizpurfle has been designed to run on an unmodified Android OS on an actual Device. The tool automatically discovers, fuzzes, and profiles proprietary services. This work evaluates the applicability and performance of Chizpurfle on the Samsung Galaxy S6 Edge, and discusses software bugs found in privileged vendor services.
Antonio Ken Iannillo - One of the best experts on this subject based on the ideXlab platform.
-
Chizpurfle: A Gray-Box Android Fuzzer for Vendor Service Customizations
2017 IEEE 28th International Symposium on Software Reliability Engineering (ISSRE), 2017Co-Authors: Antonio Ken Iannillo, Roberto Natella, Domenico Cotroneo, Cristina Nita-rotaruAbstract:Android has become the most popular mobile OS, as it enables Device manufacturers to introduce customizations to compete with value-added services. However, customizations make the OS less dependable and secure, since they can introduce software flaws. Such flaws can be found by using fuzzing, a popular testing technique among security researchers.This paper presents Chizpurfle, a novel "gray-box" fuzzing tool for vendor-specific Android services. Testing these services is challenging for existing tools, since vendors do not provide source code and the services cannot be run on a Device Emulator. Chizpurfle has been designed to run on an unmodified Android OS on an actual Device. The tool automatically discovers, fuzzes, and profiles proprietary services. This work evaluates the applicability and performance of Chizpurfle on the Samsung Galaxy S6 Edge, and discusses software bugs found in privileged vendor services.
Domenico Cotroneo - One of the best experts on this subject based on the ideXlab platform.
-
Chizpurfle: A Gray-Box Android Fuzzer for Vendor Service Customizations
2017 IEEE 28th International Symposium on Software Reliability Engineering (ISSRE), 2017Co-Authors: Antonio Ken Iannillo, Roberto Natella, Domenico Cotroneo, Cristina Nita-rotaruAbstract:Android has become the most popular mobile OS, as it enables Device manufacturers to introduce customizations to compete with value-added services. However, customizations make the OS less dependable and secure, since they can introduce software flaws. Such flaws can be found by using fuzzing, a popular testing technique among security researchers.This paper presents Chizpurfle, a novel "gray-box" fuzzing tool for vendor-specific Android services. Testing these services is challenging for existing tools, since vendors do not provide source code and the services cannot be run on a Device Emulator. Chizpurfle has been designed to run on an unmodified Android OS on an actual Device. The tool automatically discovers, fuzzes, and profiles proprietary services. This work evaluates the applicability and performance of Chizpurfle on the Samsung Galaxy S6 Edge, and discusses software bugs found in privileged vendor services.
Roberto Natella - One of the best experts on this subject based on the ideXlab platform.
-
Chizpurfle: A Gray-Box Android Fuzzer for Vendor Service Customizations
2017 IEEE 28th International Symposium on Software Reliability Engineering (ISSRE), 2017Co-Authors: Antonio Ken Iannillo, Roberto Natella, Domenico Cotroneo, Cristina Nita-rotaruAbstract:Android has become the most popular mobile OS, as it enables Device manufacturers to introduce customizations to compete with value-added services. However, customizations make the OS less dependable and secure, since they can introduce software flaws. Such flaws can be found by using fuzzing, a popular testing technique among security researchers.This paper presents Chizpurfle, a novel "gray-box" fuzzing tool for vendor-specific Android services. Testing these services is challenging for existing tools, since vendors do not provide source code and the services cannot be run on a Device Emulator. Chizpurfle has been designed to run on an unmodified Android OS on an actual Device. The tool automatically discovers, fuzzes, and profiles proprietary services. This work evaluates the applicability and performance of Chizpurfle on the Samsung Galaxy S6 Edge, and discusses software bugs found in privileged vendor services.
Max Felser - One of the best experts on this subject based on the ideXlab platform.
-
Profinet IO-Device Emulator based on the Man-in-the-middle Attack
2006 IEEE Conference on Emerging Technologies and Factory Automation, 2006Co-Authors: Michel Baud, Max FelserAbstract:A Profinet IO network of class A uses standard Ethernet network components. If these network components can be attacked by e.g. a man-in-the-middle attack, this is also the case for Profinet 10. This paper outlines these possibilities and shows, how this may be used to build IO-Device Emulators for system-testing.