Show simple item record

Smartphone App Security: Vulnerabilities and Implementations

dc.contributor.authorZhang, Linxi
dc.contributor.advisorMa, Di
dc.date.accessioned2018-05-07T20:39:36Z
dc.date.availableNO_RESTRICTIONen_US
dc.date.available2018-05-07T20:39:36Z
dc.date.issued2018-04-29
dc.date.submitted2018-04-09
dc.identifier.urihttps://hdl.handle.net/2027.42/143522
dc.description.abstractDue to the high occupancy volume of smartphones in mode society, more and more developers join the smartphone app market and develop various mobile applications that could benefit out life in many ways. However, smartphone apps are often blamed for insecurities due to smartphone technologies as well as inexperienced app developers. In this thesis work, we study smartphone app security vulnerabilities due to either improper implementations or improper use of smartphone technologies. More specifically, we study potential security vulnerabilities in three categories of apps: apps which use the secure socket layer(SSL) protocol for secure communication, apps which use the WebView technology, and apps which are HTML5-based. For each category of apps, we analyze the underlying technologies to show the cause of vulnerabilities, and develop instruction materials for each of the three validation attacks we have implemented and turn them into security teaching labs. These security teaching labs aim to help students to understand the theoretical attack concepts in and accurate and understandable way and cultivate the hacking mindset.en_US
dc.language.isoen_USen_US
dc.subjectAndroiden_US
dc.subjectApp securityen_US
dc.subjectMITMen_US
dc.subjectSSLen_US
dc.subjectWeb viewen_US
dc.subjectHTML5-based mobile applicationen_US
dc.subjectCode injectionen_US
dc.subject.otherComputer scienceen_US
dc.titleSmartphone App Security: Vulnerabilities and Implementationsen_US
dc.typeThesisen_US
dc.description.thesisdegreenameMaster of Science (MS)en_US
dc.description.thesisdegreedisciplineComputer and Information Science, College of Engineering & Computer Scienceen_US
dc.description.thesisdegreegrantorUniversity of Michigan-Dearbornen_US
dc.contributor.committeememberGuo, Jinhua
dc.contributor.committeememberWang, Shengquan
dc.identifier.uniqname10672799en_US
dc.description.bitstreamurlhttps://deepblue.lib.umich.edu/bitstream/2027.42/143522/1/Linxi-thesis-submission.pdf
dc.identifier.orcid0000-0002-6233-5266en_US
dc.description.filedescriptionDescription of Linxi-thesis-submission.pdf : Thesis
dc.identifier.name-orcidZhang, Linxi; 0000-0002-6233-5266en_US
dc.owningcollnameDissertations and Theses (Ph.D. and Master's)


Files in this item

Show simple item record

Remediation of Harmful Language

The University of Michigan Library aims to describe library materials in a way that respects the people and communities who create, use, and are represented in our collections. Report harmful or offensive language in catalog records, finding aids, or elsewhere in our collections anonymously through our metadata feedback form. More information at Remediation of Harmful Language.

Accessibility

If you are unable to use this file in its current format, please select the Contact Us link and we can modify it to make it more accessible to you.