Differential Verification of Information Flow in SEAndroid Policies
Lorenzo Ceragioli, Letterio Galletta, Edoardo Lunati
摘要
Abstract SEAndroid is deployed on almost all modern Android devices to enforce mandatory access control. The Android Open Source Project regularly publishes a predefined SEAndroid policy that each vendor customises for its devices. These customisations and policy updates may cause security regressions: even small misconfigurations may introduce new information flows leading to exploitable vulnerabilities. We propose a differential verification framework that determines whether security-relevant changes between two SEAndroid configurations affect information-flow properties as intended. Our verification framework is based on the novel comparative modal logic CML interpreted over pairs of Kripke structures. We formalise SEAndroid policies within this logic and define a suitable model-checking algorithm for differential reasoning. We implement our framework in the tool Mordente , and evaluate it on real-world SEAndroid policies.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- Trust, But Verify: A Longitudinal Analysis Of Android OEM Compliance and CustomizationAndrea Possemato, Simone Aonzo, Davide Balzarotti, Yanick FratantonioS&P 2021 · 被引用 21 次
- PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android SystemsYu Tsung Lee, William Enck, Haining Chen, Hayawardh Vijayakumar 等USENIX Security 2021 · 被引用 17 次
- SEPAL: Towards a Large-scale Analysis of SEAndroid Policy CustomizationDongsong Yu, Guangliang Yang, Guozhu Meng, Xiaorui Gong 等WWW 2021 · 被引用 10 次
- BigMAC: Fine-Grained Policy Analysis of Android FirmwareGrant Hernandez, Dave (Jing) Tian, Anurag Swarnim Yadav, Byron J. Williams 等USENIX Security 2020
相关 Paper
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang 等NDSS 2018 · 被引用 95 次
- Lost in Migration: Exposing Android Framework Vulnerabilities in Parallel Java-Kotlin ImplementationsRui Li, Wenrui Diao, Debin GaoCCS 2026
- Poirot: Probabilistically Recommending Protections for the Android FrameworkZeinab El-Rewini, Zhuo Zhang, Yousra AaferCCS 2022 · 被引用 6 次
- Characterizing and Detecting Configuration Compatibility Issues in Android AppsHuaxun Huang, Ming Wen, Lili Wei, Yepang Liu 等ASE 2021 · 被引用 15 次
- Harvesting Inconsistent Security Configurations in Custom Android ROMs via Differential AnalysisYousra Aafer, Xiao Zhang, Wenliang DuUSENIX Security 2016 · 被引用 43 次
