Chinese Journal of Network and Information Security ›› 2016, Vol. 2 ›› Issue (12): 27-38.doi: 10.11959/j.issn.2096-109x.2016.00134

• Papers • Previous Articles     Next Articles

Toward discovering and exploiting private server-side Web API

Jia CHEN1,Shan-qing1 GUO1,2   

  1. 1 School of Computer Science and Technology,Shandong University,Jinan 250101,China
    2 Key Laboratory of Cryptologic Technology and Information Security,Ministry of Education,Shandong University,Jinan 250101,China
  • Revised:2015-12-05 Online:2016-12-01 Published:2016-12-28
  • Supported by:
    TheNationalNaturalScienceFoundationofChina(91546203);The Key Science Technology Project of Shandong Province(2015GGE27033);The Independent Innovation Foundation of Shandong Province(2014CGZH1106);The Independent Innovation Foundation of Shandong Province(ZR2014FM020)

Abstract:

Most of the interfaces for mobile application and server interaction use the Web API for communication,but the Web API introduced by these mobile applications may introduce new security issues.To facilitate the study of the security of Web API,a system for automatically discovering the server-side Web API interface in APK files based on the conventional Android program testing framework was designed and implemented.This system can help to develop the research on private server-side Web API interface security.

Key words: Web API, Android App, static analysis, dynamic analysis

CLC Number: 

No Suggested Reading articles found!