A Stitch in Time

Duc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes, Charles Weir, Sascha Fahl
<span title="">2017</span> <i title="ACM Press"> <a target="_blank" rel="noopener" href="https://fatcat.wiki/container/rau5643b7ncwvh74y6p64hntle" style="color: black;">Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security - CCS &#39;17</a> </i> &nbsp;
Despite security advice in the official documentation and an extensive body of security research about vulnerabilities and exploits, many developers still fail to write secure Android applications. Frequently, Android developers fail to adhere to security best practices, leaving applications vulnerable to a multitude of attacks. We point out the advantage of a low-time-cost tool both to teach better secure coding and to improve app security. Using the FixDroid ™ IDE plug-in, we show that
more &raquo; ... ional and hobby app developers can work with and learn from an in-environment tool without it impacting their normal work; and by performing studies with both students and professional developers, we identify key UI requirements and demonstrate that code delivered with such a tool by developers previously inexperienced in security contains significantly less security problems. Perfecting and adding such tools to the Android development environment is an essential step in getting both security and privacy for the next generation of apps.
<span class="external-identifiers"> <a target="_blank" rel="external noopener noreferrer" href="https://doi.org/10.1145/3133956.3133977">doi:10.1145/3133956.3133977</a> <a target="_blank" rel="external noopener" href="https://dblp.org/rec/conf/ccs/NguyenWA0WF17.html">dblp:conf/ccs/NguyenWA0WF17</a> <a target="_blank" rel="external noopener" href="https://fatcat.wiki/release/iwbo4j2imbb67navyqqtx6w3j4">fatcat:iwbo4j2imbb67navyqqtx6w3j4</a> </span>
<a target="_blank" rel="noopener" href="https://web.archive.org/web/20200508213622/https://eprints.lancs.ac.uk/id/eprint/88075/1/CCS_FixDroid_CR.pdf" title="fulltext PDF download" data-goatcounter-click="serp-fulltext" data-goatcounter-title="serp-fulltext"> <button class="ui simple right pointing dropdown compact black labeled icon button serp-button"> <i class="icon ia-icon"></i> Web Archive [PDF] <div class="menu fulltext-thumbnail"> <img src="https://blobs.fatcat.wiki/thumbnail/pdf/2e/e5/2ee5bde630e155e00fb177648b20a24c816ac181.180px.jpg" alt="fulltext thumbnail" loading="lazy"> </div> </button> </a> <a target="_blank" rel="external noopener noreferrer" href="https://doi.org/10.1145/3133956.3133977"> <button class="ui left aligned compact blue labeled icon button serp-button"> <i class="external alternate icon"></i> acm.org </button> </a>