Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEATURE] Specify versions of data sets used #1357

Closed
ghost opened this issue Apr 14, 2020 · 1 comment
Closed

[FEATURE] Specify versions of data sets used #1357

ghost opened this issue Apr 14, 2020 · 1 comment
Assignees
Labels
enhancement MobSF enhancements and feature requests static analyzer Static Analyzer related

Comments

@ghost
Copy link

ghost commented Apr 14, 2020

Some analysis results are time-dependent; specifically, reported ratings may change with each scan. This applies at least to:

  1. all app metadata retrieved from AppStores
  2. the certificate status of the signer certificate (Android)
  3. domain malware checks (IP address, IP geolocation, status)
  4. VirusTotal results

In order to make test results verifiable and possible differences between two scans comprehensible, a consistent versioning if the data sets used is necessary.

Currently, only the scan date is specified when using the VirusTotal API.

I suggest to add the following information to JSON Report API:

  • time at which an analysis started
  • time at which an analysis was completed (since not all analysis steps are executed in the very beginning and all at once)
  • the version string (if available) and the time at which a data set was successfully updated the last time (for example, the Malware Analysis or IP Geolocation data sets may be cached)
@ghost ghost added the enhancement MobSF enhancements and feature requests label Apr 14, 2020
@ghost ghost assigned ajinabraham Apr 14, 2020
@ajinabraham ajinabraham added the static analyzer Static Analyzer related label Apr 23, 2020
@ajinabraham
Copy link
Member

Tracked Separately

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement MobSF enhancements and feature requests static analyzer Static Analyzer related
Projects
None yet
Development

No branches or pull requests

1 participant