USENIX Security2016Top-tier venue
On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification Analysis
Michael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel, Damien Octeau, Sebastian Weisgerber
Abstract
In contrast to the Android application layer, Android's application framework's internals and their influence on the platform security and user privacy are still largely a black box for us. In this paper, we establish a static runtime model of the application framework in order to study its internals and provide the first high-level classification of the framework's protected resources. We thereby uncover design patterns that differ highly from the runtime model at the application layer. We demonstrate the benefits of our insights for security-focused analysis of the framework by re-visiting the important use-case of mapping Android permissions to framework/SDK API methods. We, in particular, present a novel mapping based on our findings that significantly improves on prior results in this area that were established based on insufficient knowledge about the framework's internals. Moreover, we introduce the concept of permission locality to show that although framework services follow the principle of separation of duty, the accompanying permission checks to guard sensitive operations violate it.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2839c6ed-20b0-4e77-a7e5-c10fb20c31ccCited by top-tier papers34
- ContexloT: Towards Providing Contextual Integrity to Appified IoT PlatformsYunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati et al.NDSS 2017 · 325 citations
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 188 citations
- Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android MalwareXiaohan Zhang, Yuan Zhang, Ming Zhong, Daizong Ding et al.CCS 2020 · 173 citations
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang et al.NDSS 2018 · 95 citations
- The Rise of the Citizen Developer: Assessing the Security Impact of Online App GeneratorsMarten Oltrogge, Erik Derr, Christian Stransky, Yasemin Acar et al.S&P 2018 · 69 citations
Related papers
- Bringing Balance to the Force: Dynamic Analysis of the Android Application FrameworkAbdallah Dawoud, Sven BugielNDSS 2021
- Cross-language Android permission specificationChaoran Li, Xiao Chen, Ruoxi Sun, Minhui Xue et al.FSE 2022 · 13 citations
- Resolving the Predicament of Android Custom PermissionsGüliz Seray Tuncay, Soteris Demetriou, Karan Ganju, Carl A. GunterNDSS 2018 · 51 citations
- The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock AndroidJie Huang, Oliver Schranz, Sven Bugiel, Michael BackesCCS 2017 · 32 citations
- Finding the Missing Piece: Permission Specification Analysis for Android NDKHao Zhou, Haoyu Wang, Shuohan Wu, Xiapu Luo et al.ASE 2021 · 14 citations
