Application Security Evaluation via Obfuscation and Vulnerability Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for applications distributed through platforms like Appstore lack consistency and effectiveness in detecting obfuscation and vulnerabilities, making it difficult for application publishers to maintain a certain level of security across multiple registered applications.
Innovation Solution
A security evaluation system and method that objectively analyzes the level of security applied to registered applications by evaluating obfuscation and vulnerability perspectives, providing analysis information for security enhancement, and determining whether obfuscation is applied to various file formats such as APK, ELF, and PE files.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If simple programming language level vulnerability inspection is performed, then inspection speed is maintained, but security evaluation precision is insufficient to detect obfuscation and vulnerabilities effectively
Solution Approach 1:
The security inspection system is divided into multiple specialized modules: obfuscation detection module, vulnerability detection module, and security solution detection module. Each module focuses on specific detection tasks, enabling comprehensive security evaluation without requiring a single complex inspection system. This segmentation allows the system to achieve high precision in detecting obfuscation and vulnerabilities while maintaining manageable complexity through modular architecture.
2Adaptability or versatility
If multiple different security solutions are installed on registered applications, then adaptability to various security needs is improved, but consistency of security level across applications deteriorates
Solution Approach 1:
The system provides automated security evaluation feedback to application publishers, analyzing the security levels of registered applications across obfuscation, vulnerability, and security solution dimensions. This feedback mechanism enables publishers to understand security gaps and make consistent security improvements across their application portfolio, achieving both adaptability to different security needs and consistency in security level maintenance.
3Measurement precision
If comprehensive security analysis including obfuscation and vulnerability detection is performed, then security evaluation precision is improved, but analysis time increases
Solution Approach 1:
The system performs automated security analysis including obfuscation detection, vulnerability scanning, and security solution evaluation during the application registration process. By conducting comprehensive security analysis in advance before application distribution, the system achieves high security evaluation precision without causing time loss during application execution or updates.
Data Source
AI summary
Provided are methods and/or systems for evaluating security of an application. A security evaluation method including storing pattern-information-by-perspective for analyzing a file package based on an obfuscation perspective and a vulnerability perspective, receiving a registration on the file package to be distributed to users for installing and executing an application, analyzing the registered file package based on the pattern-information-by-perspective and generating analysis information of the obfuscation perspective and analysis information of the vulnerability perspective, and providing the generated analysis information of the obfuscation perspective and the analysis information of the vulnerability perspective may be provided.


