SO{U}RCERER: Developer-Driven Security Testing Framework for Android Apps
Muhammad Sajidur Rahman, Blas Kojusner, Ryon Kennedy, Prerit Pathak,, Lin Qi, Byron Williams

TL;DR
SO{U}RCERER is a developer-centric framework that guides Android app developers in identifying, prioritizing, and mitigating security vulnerabilities effectively without requiring extensive security expertise or resources.
Contribution
It introduces a practical, developer-driven security testing framework tailored for Android apps that improves vulnerability prioritization and mitigation without heavy resource demands.
Findings
Reduces security warnings by 24-61% compared to static analysis alone.
Provides actionable vulnerability lists focused on critical assets.
Demonstrates viability for small to medium app development teams.
Abstract
Frequently advised secure development recommendations often fall short in practice for app developers. Tool-driven (e.g., using static analysis tools) approaches lack context and domain-specific requirements of an app being tested. App developers struggle to find an actionable and prioritized list of vulnerabilities from a laundry list of security warnings reported by static analysis tools. Process-driven (e.g., applying threat modeling methods) approaches require substantial resources (e.g., security testing team, budget) and security expertise, which small to medium-scale app dev teams could barely afford. To help app developers securing their apps, we propose SO{U}RCERER, a guiding framework for Android app developers for security testing. SO{U}RCERER guides developers to identify domain-specific assets of an app, detect and prioritize vulnerabilities, and mitigate those…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
