Precise Android API Protection Mapping Derivation and Reasoning
Yousra Aafer, Guanhong Tao, Jianjun Huang, Xiangyu Zhang, Ninghui Li
Abstract
The Android research community has long focused on building an Android API permission specification, which can be leveraged by app developers to determine the optimum set of permissions necessary for a correct and safe execution of their app. However, while prominent existing efforts provide a good approximation of the permission specification, they suffer from a few shortcomings. Dynamic approaches cannot generate complete results, although accurate for the particular execution. In contrast, static approaches provide better coverage, but produce imprecise mappings due to their lack of path-sensitivity. In fact, in light of Android's access control complexity, the approximations hardly abstract the actual co-relations between enforced protections. To address this, we propose to precisely derive Android protection specification in a pathsensitive fashion, using a novel graph abstraction technique. We further showcase how we can apply the generated maps to tackle security issues through logical satisfiability reasoning. Our constructed maps for 4 Android Open Source Project (AOSP) images highlight the significance of our approach, as ∼41% of APIs' protections cannot be correctly modeled without our technique.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 274c8a44-9534-48a0-aa90-d96ba828a129Cited by top-tier papers14
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang et al.CCS 2020 · 48 citations
- APER: Evolution-Aware Runtime Permission Misuse Detection for Android AppsSinan Wang, Yibo Wang, Xian Zhan, Ying Wang et al.ICSE 2022 · 19 citations
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis et al.USENIX Security 2024 · 13 citations
- Cerberus: Query-driven Scalable Vulnerability Detection in OAuth Service Provider ImplementationsTamjid Al Rahat, Yu Feng, Yuan TianCCS 2022 · 12 citations
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 9 citations
Builds on4
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang et al.NDSS 2018 · 95 citations
- Kratos: Discovering Inconsistent Security Policy Enforcement in the Android FrameworkYuru Shao, Qi Alfred Chen, Zhuoqing Morley Mao, Jason Ott et al.NDSS 2016 · 85 citations
- Life after App Uninstallation: Are the Data Still Alive? Data Residue Attacks on AndroidXiao Zhang, Kailiang Ying, Yousra Aafer, Zhenshen Qiu et al.NDSS 2016 · 34 citations
Related papers
- Cross-language Android permission specificationChaoran Li, Xiao Chen, Ruoxi Sun, Minhui Xue et al.FSE 2022 · 13 citations
- Finding the Missing Piece: Permission Specification Analysis for Android NDKHao Zhou, Haoyu Wang, Shuohan Wu, Xiapu Luo et al.ASE 2021 · 14 citations
- DocFlow: Extracting Taint Specifications from Software DocumentationMarcos Tileria, Jorge Blasco, Santanu Kumar DashICSE 2024 · 5 citations
- Ariadne: Navigating through the Labyrinth of Data-Driven Customization Inconsistencies in AndroidParjanya Vyas, Haseeb Ur Rehman Faheem, Yousra Aafer, N. AsokanUSENIX Security 2025
- Auditing Framework APIs via Inferred App-side Security SpecificationsParjanya Vyas, Asim Waheed, Yousra Aafer, N. AsokanUSENIX Security 2023
