The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock Android
Jie Huang, Oliver Schranz, Sven Bugiel, Michael Backes
Abstract
Third-party libraries are commonly used by app developers for alleviating the development efforts and for monetizing their apps. On Android, the host app and its third-party libraries reside in the same sandbox and share all privileges awarded to the host app by the user, putting the users' privacy at risk of intrusions by third-party libraries. In this paper, we introduce a new privilege separation approach for third-party libraries on stock Android. Our solution partitions Android applications at compile-time into isolated, privilege-separated compartments for the host app and the included third-party libraries. A particular benefit of our approach is that it leverages compiler-based instrumentation available on stock Android versions and thus abstains from modification of the SDK, the app bytecode, or the device firmware. A particular challenge for separating libraries from their host apps is the reconstruction of the communication channels and the preservation of visual fidelity between the now separated app and its libraries. We solve this challenge through new IPC-based protocols to synchronize layout and lifecycle management between different sandboxes. Finally, we demonstrate the efficiency and effectiveness of our solution by applying it to real world apps from the Google Play Store that contain advertisements.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5ede7b5c-4e9d-491d-8833-c5b5e2f7e159Cited by top-tier papers15
- DynPTA: Combining Static and Dynamic Analysis for Practical Selective Data ProtectionTapti Palit, Jarin Firose Moon, Fabian Monrose, Michalis PolychronakisS&P 2021 · 48 citations
- Understanding Malicious Cross-library Data Harvesting on AndroidJice Wang, Yue Xiao, Xueqiang Wang, Yuhong Nan et al.USENIX Security 2021 · 41 citations
- PKRU-safe: automatically locking down the heap between safe and unsafe languagesPaul Kirth, Mitchel Dickerson, Stephen Crane, Per Larsen et al.EuroSys 2022 · 41 citations
- How does misconfiguration of analytic services compromise mobile privacy?Xueling Zhang, Xiaoyin Wang, Rocky Slavin, Travis D. Breaux et al.ICSE 2020 · 21 citations
- DroidCap: OS Support for Capability-based Permissions in AndroidAbdallah Dawoud, Sven BugielNDSS 2019 · 17 citations
Builds on4
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- FLEXDROID: Enforcing In-App Privilege Separation in AndroidJaebaek Seo, Daehyeok Kim, Donghyun Cho, Insik Shin et al.NDSS 2016 · 114 citations
- What Mobile Ads Know About Mobile UsersSooel Son, Daehyeok Kim, Vitaly ShmatikovNDSS 2016 · 101 citations
- Free for All! Assessing User Data Exposure to Advertising Libraries on AndroidSoteris Demetriou, Whitney Merrill, Wei Yang, Aston Zhang et al.NDSS 2016 · 95 citations
Related papers
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- Union under Duress: Understanding Hazards of Duplicate Resource Mismediation in Android Software Supply ChainXueqiang Wang, Yifan Zhang, XiaoFeng Wang, Yan Jia et al.USENIX Security 2023
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- LibScan: Towards More Precise Third-Party Library Identification for Android ApplicationsYafei Wu, Cong Sun, Dongrui Zeng, Gang Tan et al.USENIX Security 2023
- DocFlow: Extracting Taint Specifications from Software DocumentationMarcos Tileria, Jorge Blasco, Santanu Kumar DashICSE 2024 · 5 citations
