Borrowing your enemy's arrows: the case of code reuse in Android via direct inter-app code invocation
Jun Gao, Li Li, Pingfan Kong, Tegawendé F. Bissyandé, Jacques Klein
Abstract
The Android ecosystem offers different facilities to enable communication among app components and across apps to ensure that rich services can be composed through functionality reuse. At the heart of this system is the Inter-component communication (ICC) scheme, which has been largely studied in the literature. Less known in the community is another powerful mechanism that allows for direct inter-app code invocation which opens up for different reuse scenarios, both legitimate or malicious. This paper exposes the general workflow for this mechanism, which beyond ICCs, enables app developers to access and invoke functionalities (either entire Java classes, methods or object fields) implemented in other apps using official Android APIs. We experimentally showcase how this reuse mechanism can be leveraged to “plagiarize" supposedly-protected functionalities. Typically, we were able to leverage this mechanism to bypass security guards that a popular video broadcaster has placed for preventing access to its video database from outside its provided app. We further contribute with a static analysis toolkit, named DICIDer, for detecting direct inter-app code invocations in apps. An empirical analysis of the usage prevalence of this reuse mechanism is then conducted. Finally, we discuss the usage contexts as well as the implications of this studied reuse mechanism.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0c7bdcfc-fe01-4884-a317-bf2842dcb3c3Cited by top-tier papers1
Ask how each one uses itRelated papers
- RAICC: Revealing Atypical Inter-Component Communication in Android AppsJordan Samhi, Alexandre Bartel, Tegawendé F. Bissyandé, Jacques KleinICSE 2021 · 3 citations
- A Comprehensive Evaluation of Android ICC Resolution TechniquesJiwei Yan, Shixin Zhang, Yepang Liu, Xi Deng et al.ASE 2022 · 15 citations
- Static asynchronous component misuse detection for Android applicationsLinjie Pan, Baoquan Cui, Hao Liu, Jiwei Yan et al.FSE 2020 · 10 citations
- The Misuse of Android Unix Domain Sockets and Security ImplicationsYuru Shao, Jason Ott, Yunhan Jack Jia, Zhiyun Qian et al.CCS 2016 · 41 citations
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen et al.CCS 2018 · 93 citations
