USENIX Security2023Top-tier venue
Auditing Framework APIs via Inferred App-side Security Specifications
Parjanya Vyas, Asim Waheed, Yousra Aafer, N. Asokan
Abstract
In this work, we explore auditing access control implementations of Android private framework APIs by leveraging app-side security specifications. The seemingly straightforward auditing task faces significant challenges. It requires extracting unconventional security indicators and understanding their relevance to private framework APIs. More importantly, addressing these challenges requires relying on uncertain hints. We hence, introduce Bluebird, a security auditing platform for Android APIs, that mimics a human expert. Bluebird seamlessly fuses human-like understanding of app-side logic with statically-derived program semantics using probabilistic inference to detect access control gaps in private APIs. 1 Henceforth, we use the term "security specification" in a broad sense to refer to the security policy that can be inferred from access control enforcement or other sensitivity indicators, rather than to a formal, written, security specification in the traditional sense. 2 An app component or a UI block.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f7c183c5-21ba-4746-a846-0209dcfaaeabCited by top-tier papers3
- Ariadne: Navigating through the Labyrinth of Data-Driven Customization Inconsistencies in AndroidParjanya Vyas, Haseeb Ur Rehman Faheem, Yousra Aafer, N. AsokanUSENIX Security 2025
- A Longitudinal Analysis Of Replicas in the Wild Wild AndroidSyeda Mashal Abbas Zaidi, Shahpar Khan, Parjanya Vyas, Yousra AaferASE 2024
- Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIsZhiao Wei, Chao Wang, Haseeb-Ur-Rehman Faheem, Luyi Xing et al.USENIX Security 2026
Builds on8
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang et al.NDSS 2018 · 95 citations
- Kratos: Discovering Inconsistent Security Policy Enforcement in the Android FrameworkYuru Shao, Qi Alfred Chen, Zhuoqing Morley Mao, Jason Ott et al.NDSS 2016 · 85 citations
- OSPREY: Recovery of Variable and Data Structure via Probabilistic Analysis for Stripped BinaryZhuo Zhang, Yapeng Ye, Wei You, Guanhong Tao et al.S&P 2021 · 78 citations
- Precise Android API Protection Mapping Derivation and ReasoningYousra Aafer, Guanhong Tao, Jianjun Huang, Xiangyu Zhang et al.CCS 2018 · 51 citations
Related papers
- Poirot: Probabilistically Recommending Protections for the Android FrameworkZeinab El-Rewini, Zhuo Zhang, Yousra AaferCCS 2022 · 6 citations
- DocFlow: Extracting Taint Specifications from Software DocumentationMarcos Tileria, Jorge Blasco, Santanu Kumar DashICSE 2024 · 5 citations
- PriAgent: A Collaborative Multi-Agent Framework for Auditing Android Privacy ComplianceZiwei Zhang, Zhao Li, Zhuojun Jiang, Jiangyi Yin et al.AAAI 2026
- Bringing Balance to the Force: Dynamic Analysis of the Android Application FrameworkAbdallah Dawoud, Sven BugielNDSS 2021
- Uncovering Cross-Context Inconsistent Access Control Enforcement in AndroidHao Zhou, Haoyu Wang, Xiapu Luo, Ting Chen et al.NDSS 2022
