FM2024Top-tier venue
Automated Repair of Information Flow Security in Android Implicit Inter-App Communication
Abhishek Tiwari, Jyoti Prakash, Zhen Dong, Carlo A. Furia
Abstract
Abstract Android’s intents provide a form of inter-app communication with implicit, capability-based matching of senders and receivers. Such kind of implicit addressing provides some much-needed flexibility but also increases the risk of introducing information flow security bugs and vulnerabilities—as there is no standard way to specify what permissions are required to access the data sent through intents, so that it is handled properly. To mitigate such risks of intent-based communication, this paper introduces IntentRepair, an automated technique to detect such information flow security leaks and to automatically repair them. IntentRepair first finds sender and receiver modules that may communicate via intents, and such that the sender sends sensitive information that the receiver forwards to a public channel. To prevent this flow, IntentRepair patches the sender so that it also includes information about the permissions needed to access the data; and the receiver so that it will only disclose the sensitive information if it possesses the required permissions. We evaluated a prototype implementation of IntentRepair on 869 Android open-source apps, showing that it is effective in automatically detecting and repairing information flow security bugs that originate in implicit intent-based communication, introducing only a modest overhead in terms of patch size.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c0d1362c-0c35-4769-9ec2-c406e7104638Builds on5
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- GUIDER: GUI structure and vision co-guided test script repair for Android appsTongtong Xu, Minxue Pan, Yu Pei, Guiyin Li et al.ISSTA 2021 · 30 citations
- Towards Automatically Repairing Compatibility Issues in Published Android AppsYanjie Zhao, Li Li, Kui Liu, John C. GrundyICSE 2022 · 25 citations
- Detecting and fixing data loss issues in Android appsWunan Guo, Zhen Dong, Liwei Shen, Wei Tian et al.ISSTA 2022 · 17 citations
- ConfFix: Repairing Configuration Compatibility Issues in Android AppsHuaxun Huang, Chi Xu, Ming Wen, Yepang Liu et al.ISSTA 2023 · 10 citations
Related papers
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 9 citations
- MALintent: Coverage Guided Intent Fuzzing Framework for AndroidAmmar Askar, Fabian Fleischer, Christopher Kruegel, Giovanni Vigna et al.NDSS 2025
- The Misuse of Android Unix Domain Sockets and Security ImplicationsYuru Shao, Jason Ott, Yunhan Jack Jia, Zhiyun Qian et al.CCS 2016 · 41 citations
- Keeping Secrets: Multi-objective Genetic Improvement for Detecting and Reducing Information LeakageIbrahim Mesecan, Daniel Blackwell, David Clark, Myra B. Cohen et al.ASE 2022 · 5 citations
- RAICC: Revealing Atypical Inter-Component Communication in Android AppsJordan Samhi, Alexandre Bartel, Tegawendé F. Bissyandé, Jacques KleinICSE 2021 · 3 citations
