Cross-language Android permission specification
Chaoran Li, Xiao Chen, Ruoxi Sun, Minhui Xue, Sheng Wen, Muhammad Ejaz Ahmed, Seyit Camtepe, Yang Xiang
摘要
The Android system manages access to sensitive APIs by permission enforcement. An application (app) must declare proper permissions before invoking specific Android APIs. However, there is no official documentation providing the complete list of permission-protected APIs and the corresponding permissions to date. Researchers have spent significant efforts extracting such API protection mapping from the Android API framework, which leverages static code analysis to determine if specific permissions are required before accessing an API. Nevertheless, none of them has attempted to analyze the protection mapping in the native library (i.e., code written in C and C++), an essential component of the Android framework that handles communication with the lower-level hardware, such as cameras and sensors. While the protection mapping can be utilized to detect various security vulnerabilities in Android apps, such as permission over-privilege, imprecise mapping will lead to false results in detecting such security vulnerabilities. To fill this gap, we thereby propose to construct the protection mapping involved in the native libraries of the Android framework to present a complete and accurate specification of Android API protection. We develop a prototype system, named NatiDroid, to facilitate the cross-language static analysis and compare its performance with two state-of-the-practice tools, termed Axplorer and Arcade. We evaluate NatiDroid on more than 11,000 Android apps, including system apps from custom Android ROMs and third-party apps from the Google Play. Our NatiDroid can identify up to 464 new API-permission mappings, in contrast to the worst-case results derived from both Axplorer and Arcade, where approximately 71% apps have at least one false positive in permission over-privilege. We have disclosed all the potential vulnerabilities detected to the stakeholders.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper2
- Not Seen, Not Heard in the Digital World! Measuring Privacy Practices in Children's AppsRuoxi Sun, Minhui Xue, Gareth Tyson, Shuo Wang 等WWW 2023 · 被引用 15 次
- Call Graph Soundness in Android Static AnalysisJordan Samhi, René Just, Tegawendé F. Bissyandé, Michael D. Ernst 等ISSTA 2024 · 被引用 8 次
相关 Paper
- Precise Android API Protection Mapping Derivation and ReasoningYousra Aafer, Guanhong Tao, Jianjun Huang, Xiangyu Zhang 等CCS 2018 · 被引用 51 次
- Finding the Missing Piece: Permission Specification Analysis for Android NDKHao Zhou, Haoyu Wang, Shuohan Wu, Xiapu Luo 等ASE 2021 · 被引用 14 次
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen 等CCS 2018 · 被引用 93 次
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel 等USENIX Security 2016 · 被引用 161 次
- DocFlow: Extracting Taint Specifications from Software DocumentationMarcos Tileria, Jorge Blasco, Santanu Kumar DashICSE 2024 · 被引用 5 次
