
بررسی کتاب Fuzzing Android: راهنمای جامع کشف آسیبپذیریها در اندروید
امنیت در سیستمعامل اندروید به دلیل گستردگی و پیچیدگی ساختار، همواره یکی از جذابترین و چالشبرانگیزترین حوزهها برای متخصصان تست نفوذ و محققان امنیتی بوده است. کتاب “Fuzzing Android: Finding Vulnerabilities in Userspace and the Kernel” یکی از جدیدترین و معتبرترین منابع آموزشی است که توسط انتشارات No Starch Press منتشر شده و به صورت تخصصی به تکنیکهای پیشرفته فازینگ (Fuzzing) در محیط اندروید میپردازد. اگر به دنبال ارتقای مهارتهای خود در کشف حفرههای امنیتی در سطح کاربر (Userspace) و هسته (Kernel) اندروید هستید، این کتاب نقشه راه شماست.
چرا کتاب Fuzzing Android را بخوانیم؟
فازینگ یکی از موثرترین روشها برای شناسایی باگهای نرمافزاری است که با تزریق دادههای تصادفی به ورودی برنامهها، سعی در کرش دادن یا شناسایی رفتارهای غیرعادی دارد. این کتاب فراتر از تئوری رفته و شما را وارد دنیای عملیاتی تست امنیت سیستمعامل اندروید میکند.
بخشهای اصلی کتاب: نگاهی به سرفصلها
این کتاب محتوای خود را در سه بخش کلیدی تقسیمبندی کرده است تا مخاطب بتواند از مفاهیم پایه به سمت پروژههای پیچیده پیش برود:
بخش اول: مقدمهای بر فازینگ
در این بخش، خواننده با الفبای فازینگ آشنا میشود.
- فصل ۱: فازینگ چیست؟
- فصل ۲: آمادهسازی محیط اندروید برای فازینگ.
- فصل ۳: معرفی ابزارها و فریمورکهای ضروری.
بخش دوم: تست کامپوننتهای اندروید
در این بخش، تمرکز از مبانی به سمت بررسی ساختار امنیتی اندروید و نوشتن کدهای تست (Harness) تغییر میکند.
- فصل ۴: بررسی کلی امنیت در اندروید.
- فصل ۵: استراتژیهای انتخاب تارگت (Target).
- **ف باگها (Bug Triage).
بخش سوم: تارگتهای پیشرفته و مدرن
این بخش برای محققان حرفهای طراحی شده است که قصد دارند به لایههای زیرین نفوذ کنند.
- فصل ۸: بررسی سرویسهای سیستم (System Services).
- فصل ۹: امنیت فصل ۸: بررسی سرویسهای سیستم (System Services).
- فصل ۹: امنیت هسته اندروید (Android Kernel).
- فصل ۱۰: آموزش نوشتن توصیفگر برای Syzkaller.
- فصل ۱۱: فازینگ مبتنی بر هاست.
- فصل ۱۲: فازینگ در عصر هوش مصنوعی.
این کتاب مناسب چه کسانی است؟
- متخصصان تست نفوذ (Pentester): برای درک عمیقتر از حفرههای امنیتی سیستمعامل.
- مهندسان امنیت موبایل: برای ایمنسازی اپلیکیشنها و سیستمعامل اندروید.
- محققان آسیبپذیری: برای یادگیری روشهای نوین فازینگ و خودکارسازی فرآیند کشف باگ.
- علاقهمندان به Kernel Hacking: کسانی که میخواهند بدانند چگونه باگهای هسته لینوکس و اندروید را شناسایی کنند.
کتاب Fuzzing Android تنها یک کتاب آموزشی نیست؛ بلکه یک مرجع عملیاتی است که به شما کمک میکند از ابزارهای قدرتمندی مانند Syzkaller به بهترین شکل استفاده کنید. اگر قصد دارید در دنیای امنیت موبایل حرفی برای گفتن داشته باشید، مطالعه این اثر از انتشارات معتبر No Starch Press یک ضرورت است.
🎓 لینک دانلود کتاب Fuzzing Android: Finding Vulnerabilities in Userspace and the Kernel
Price: $54.99
Publisher: nostarch
By: Hamzeh Zawawy, Eugene Rodionov, Xuan Xing, Kris Alder, Cory Barker, and Steven Moreland
Format: EPUB, PDF Convert
ISBN-13: 9781718505292
Android is three billion devices of hardened, audited, relentlessly defended code, and fuzzing brings it down anyway. The method is brutally simple: Bury the system in malformed input, and wait for the rare case that cracks something open. Every crash is a lead, and behind it is usually a way in.
The Google engineers who authored this book do that for a living. They’ve fuzzed Android’s Binder IPC, the Pixel modem, the GPU drivers, and the kernel, uncovering root-level vulnerabilities the architecture was supposed to keep out of reach, and now they show you how they work.
Most fuzzing books stop at the concept; this one runs the campaign. You’ll learn how to:
- Build reproducible fuzzing environments across emulators and physical devices
- Target Android’s Binder IPC, native system services, GPU drivers, and kernel interfaces
- Instrument code for coverage using AFL++ or libFuzzer and extend Syzkaller to reach new kernel drivers
- Triage, reproduce, and investigate crashes to uncover real vulnerabilities
- Develop the judgment to choose high- value targets and bypass runtime checks when appropriate.
Whether you’re a security researcher, an OEM security engineer, or a bug bounty hunter, Fuzzing Android is your operational playbook for finding vulnerabilities in the world’s largest mobile platform.
Covers: Android 17+ and is backward compatible with earlier AOSP releases.
Requires: A physical Android device or emulator (Cuttlefish); all required tools are open source.
Author Bio
Hamzeh Zawawy, PhD; Kris Alder; and Cory Barker work on the Android Blue Team, doing platform hardening, kernel security, fuzzing, and AI-driven vulnerability remediation.
Xuan Xing and Eugene Rodionov, PhD, specialize in offensive security research, fuzzing low-level Android and Pixel components, and GPU/Binder exploitation.
Steven Moreland spent nearly a decade leading Android C++ service fuzzing and redesigning its inter-process communication models.
Table of contents
Foreword
Acknowledgments
Introduction
Part I: Introduction to Fuzzing
Chapter 1: What is Fuzzing?
Chapter 2: Preparing Android for Fuzzing
Chapter 3: Tools and Frameworks
Part II: Testing Android Components
Chapter 4: An Overview of Android Security
Chapter 5: Choosing Your Target
Chapter 6: Writing Your First Android Fuzz Harness
Chapter 7: Crash Analysis and Bug Triage
Part III: Advanced Targets
Chapter 8: System Services
Chapter 9: The Android Kernel
Chapter 10: Writing a Syzkaller Description
Chapter 11: Host-Based Fuzzing
Chapter 12: Fuzzing in the Age of AI

