APER: Evolution-Aware Runtime Permission Misuse Detection for Android Apps
Sinan Wang, Yibo Wang, Xian Zhan, Ying Wang, Yepang Liu, Xiapu Luo, Shing-Chi Cheung
摘要
The Android platform introduces the runtime permission model in version 6.0. The new model greatly improves data privacy and user experience, but brings new challenges for app developers. First, it allows users to freely revoke granted permissions. Hence, developers cannot assume that the permissions granted to an app would keep being granted. Instead, they should make their apps carefully check the permission status before invoking dangerous APIs. Second, the permission specification keeps evolving, bringing new types of compatibility issues into the ecosystem. To understand the impact of the challenges, we conducted an empirical study on 13,352 popular Google Play apps. We found that 86.0% apps used dangerous APIs asynchronously after permission management and 61.2% apps used evolving dangerous APIs. If an app does not properly handle permission revocations or platform differences, unexpected runtime issues may happen and even cause app crashes. We call such Android Runtime Permission issues as ARP bugs. Unfortunately, existing runtime permission issue detection tools cannot effectively deal with the ARP bugs induced by asynchronous permission management and permission specification evolution. To fill the gap, we designed a static analyzer, Aper, that performs reaching definition and dominator analysis on Android apps to detect the two types of ARP bugs. To compare Aper with existing tools, we built a benchmark, ARPfix, from 60 real ARP bugs. Our experiment results show that Aper significantly outperforms two academic tools, ARPDroid and RevDroid, and an industrial tool, Lint, on ARPfix, with an average improvement of 46.3% on 𝐹 1score. In addition, Aper successfully found 34 ARP bugs in 214 opensource Android apps, most of which can result in abnormal app This work has been accepted to ICSE 2022. behaviors (such as app crashes) according to our manual validation. We reported these bugs to the app developers. So far, 17 bugs have been confirmed and seven have been fixed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy RamificationsMohammad Tahaei, Ruba Abu-Salma, Awais RashidCHI 2023 · 被引用 36 次
- A Comprehensive Study of Learning-based Android Malware Detectors under Challenging EnvironmentsCuiying Gao, Gaozhun Huang, Heng Li, Bang Wu 等ICSE 2024 · 被引用 29 次
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis 等USENIX Security 2024 · 被引用 13 次
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 被引用 1 次
- EP-Detector: Automatic Detection of Error-Prone Operation Anomalies in Android ApplicationsChenkai Guo, Qianlu Wang, Naipeng Dong, Lingling Fan 等ICSE 2025 · 被引用 1 次
它引用的顶会 Paper6
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel 等USENIX Security 2016 · 被引用 161 次
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu 等ICSE 2021 · 被引用 85 次
- Automated Third-Party Library Detection for Android Applications: Are We There Yet?Xian Zhan, Lingling Fan, Tianming Liu, Sen Chen 等ASE 2020 · 被引用 55 次
- Precise Android API Protection Mapping Derivation and ReasoningYousra Aafer, Guanhong Tao, Jianjun Huang, Xiangyu Zhang 等CCS 2018 · 被引用 51 次
- Understanding and finding system setting-related defects in Android appsJingling Sun, Ting Su, Junxin Li, Zhen Dong 等ISSTA 2021 · 被引用 35 次
相关 Paper
- PermDroid: automatically testing permission-related behaviour of Android applicationsShuaihao Yang, Zigang Zeng, Wei SongISSTA 2022 · 被引用 10 次
- Cross-language Android permission specificationChaoran Li, Xiao Chen, Ruoxi Sun, Minhui Xue 等FSE 2022 · 被引用 13 次
- Resolving the Predicament of Android Custom PermissionsGüliz Seray Tuncay, Soteris Demetriou, Karan Ganju, Carl A. GunterNDSS 2018 · 被引用 51 次
- How Android developers handle evolution-induced API compatibility issues: a large-scale studyHao Xia, Yuan Zhang, Yingtian Zhou, Xiaoting Chen 等ICSE 2020 · 被引用 38 次
- Android Custom Permissions Demystified: From Privilege Escalation to Design ShortcomingsRui Li, Wenrui Diao, Zhou Li, Jianqi Du 等S&P 2021 · 被引用 32 次
