Using Malware Analysis to Tailor SQUARE for Mobile Platforms

Abstract

As the number of mobile-device software applications has grown, so has the amount of malware targeting them. More than 650,000 pieces of malware now target the Android platform. As mobile malware becomes more sophisticated and begins to approach threat levels seen on PC platforms, software development security practices for mobile applications will need to adopt the security practices for PC applications to reduce consumers' exposure to financial and privacy breaches on mobile platforms. This technical note explores the development of security requirements for the K-9 Mail application, an open source email client for the Android operating system. The project's case study (1) used the Security Quality Requirements Engineering (SQUARE) methodology to develop K-9 Mail's security requirements and (2) used malware analysis to identify new security requirements in a proposed extension to the SQUARE process. This second task analyzed the impacts of DroidCleaner, a piece of Android malware, on the security goals of the K-9 Mail application. Based on the findings, new requirements are created to ensure that similar malware cannot compromise the privacy and confidentiality of email contents.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Nov 01, 2014
Accession Number
ADA614582

Entities

People

  • Gregory P. Alice
  • Nancy R. Mead

Organizations

  • Carnegie Mellon University

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Application Software
  • Case Studies
  • Computer Programming
  • Computer Programs
  • Computers
  • Malware
  • Mobile Application Software
  • Mobile Computing
  • Mobile Devices
  • Mobile Operating Systems
  • Mobile Phones
  • Mobile Software
  • Operating Systems
  • Risk Analysis
  • Smartphones
  • Software Development
  • Text Messaging

Fields of Study

  • Computer science
  • Engineering

Readers

  • Agent-Based Social Robotics and Mobile-Assisted Learning in Virtual Environments.
  • Government and Public Administration Law.

Technology Areas

  • Cyber