Uncovering Cross-Context Inconsistent Access Control Enforcement in Android
Hao Zhou, Haoyu Wang, Xiapu Luo, Ting Chen, Yajin Zhou, Ting Wang
Abstract
—Due to the complexity resulted from the huge code base and the multi-context nature of Android, inconsistent access control enforcement exists in Android, which can be exploited by malware to bypass the access control and perform unauthorized security-sensitive operations. Unfortunately, existing studies only focus on the inconsistent access control enforcement in the Java context of Android. In this paper, we conduct the first systematic investigation on the inconsistent access control enforcement across the Java context and native context of Android. In particular, to automatically discover cross-context inconsistencies, we design and implement IAceFinder , a new tool that extracts and contrasts the access control enforced in the Java context and native context of Android. Applying IAceFinder to 14 open-source Android ROM s, we find that it can effectively uncover their cross-context inconsistent access control enforcement. Specifically, IAceFinder discovers 23 inconsistencies that can be abused by attackers to compromise the device and violate user privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 366c6f9b-8754-4b43-b28e-647e2e7d0ee2Cited by top-tier papers8
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 9 citations
- Poirot: Probabilistically Recommending Protections for the Android FrameworkZeinab El-Rewini, Zhuo Zhang, Yousra AaferCCS 2022 · 6 citations
- Exploring ChatGPT App Ecosystem: Distribution, Deployment and SecurityChuan Yan, Ruomai Ren, Mark Huasong Meng, Liuhuo Wan et al.ASE 2024 · 3 citations
- Ariadne: Navigating through the Labyrinth of Data-Driven Customization Inconsistencies in AndroidParjanya Vyas, Haseeb Ur Rehman Faheem, Yousra Aafer, N. AsokanUSENIX Security 2025
- A Longitudinal Analysis Of Replicas in the Wild Wild AndroidSyeda Mashal Abbas Zaidi, Shahpar Khan, Parjanya Vyas, Yousra AaferASE 2024
Builds on9
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang et al.NDSS 2018 · 95 citations
- Kratos: Discovering Inconsistent Security Policy Enforcement in the Android FrameworkYuru Shao, Qi Alfred Chen, Zhuoqing Morley Mao, Jason Ott et al.NDSS 2016 · 85 citations
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung et al.USENIX Security 2019 · 77 citations
- An empirical assessment of security risks of global Android banking appsSen Chen, Lingling Fan, Guozhu Meng, Ting Su et al.ICSE 2020 · 70 citations
Related papers
- Cross-language Android permission specificationChaoran Li, Xiao Chen, Ruoxi Sun, Minhui Xue et al.FSE 2022 · 13 citations
- Post-GDPR Threat Hunting on Android Phones: Dissecting OS-level Safeguards of User-unresettable IdentifiersMark Huasong Meng, Qing Zhang, Guangshuai Xia, Yuwei Zheng et al.NDSS 2023
- Harvesting Inconsistent Security Configurations in Custom Android ROMs via Differential AnalysisYousra Aafer, Xiao Zhang, Wenliang DuUSENIX Security 2016 · 43 citations
- FReD: Identifying File Re-Delegation in Android System ServicesSigmund Albert Gorski III, Seaver Thorn, William Enck, Haining ChenUSENIX Security 2022
- What's Done Is Not What's Claimed: Detecting and Interpreting Inconsistencies in App BehaviorsChang Yue, Kai Chen, Zhixiu Guo, Jun Dai et al.NDSS 2025
