μSE: Mutation-based Evaluation of Security-focused Static Analysis Tools for AndroidDemonstration
This demo paper presents the technical details and usage scenarios of μSE: a mutation-based tool for evaluating security-focused static analysis tools for Android. Mutation testing is generally used by software practitioners to assess the robustness of a given test-suite. However, we leverage this technique to systematically evaluate static analysis tools and uncover and document soundness issues. μSE’s analysis has found 25 previously undocumented flaws in static data leak detection tools for Android. μSE offers four mutation schemes, namely Reachability, Complex-reachability, TaintSink, and ScopeSink, which determine the locations of seeded mutants. Furthermore, the user can extend μSE by customizing the API calls targeted by the mutation analysis. μSE is also practical, as it makes use of filtering techniques based on compilation and execution criteria that reduces the number of ineffective mutations.
Thu 27 MayDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
18:45 - 19:15 | 3.2. Testing 1DEMO - Demonstrations at Demonstration Room Chair(s): Francisco Servant Virginia Tech Each demo makes a 1-minute presentation (displayed in the Demonstration room). At the end of each presentation, a breakout room will be created for each demo. Attendees will be able to join and discuss with the authors. | ||
18:45 30mDemonstration | Efficient Fuzz Testing for Apache Spark Using Framework AbstractionDemonstration DEMO - Demonstrations Qian Zhang University of California, Los Angeles, Jiyuan Wang University of California, Los Angeles, Muhammad Ali Gulzar Virginia Tech, Rohan Padhye Carnegie Mellon University, Miryung Kim University of California at Los Angeles, USA Pre-print Media Attached | ||
18:45 30mDemonstration | Quartermaster: A Tool for Modeling and Simulating System DegradationDemonstration DEMO - Demonstrations Pre-print Media Attached | ||
18:45 30mDemonstration | μSE: Mutation-based Evaluation of Security-focused Static Analysis Tools for AndroidDemonstration DEMO - Demonstrations Amit Seal Ami William & Mary, Kaushal Kafle College of William & Mary, Kevin Moran George Mason University, Adwait Nadkarni William & Mary, Denys Poshyvanyk College of William & Mary Pre-print Media Attached |