Automated Repair of Information Flow Security in Android Implicit Inter-App Communication
Abhishek Tiwari, Jyoti Prakash, Zhen Dong, Carlo A. Furia
摘要
Abstract Android’s intents provide a form of inter-app communication with implicit, capability-based matching of senders and receivers. Such kind of implicit addressing provides some much-needed flexibility but also increases the risk of introducing information flow security bugs and vulnerabilities—as there is no standard way to specify what permissions are required to access the data sent through intents, so that it is handled properly. To mitigate such risks of intent-based communication, this paper introduces IntentRepair, an automated technique to detect such information flow security leaks and to automatically repair them. IntentRepair first finds sender and receiver modules that may communicate via intents, and such that the sender sends sensitive information that the receiver forwards to a public channel. To prevent this flow, IntentRepair patches the sender so that it also includes information about the permissions needed to access the data; and the receiver so that it will only disclose the sensitive information if it possesses the required permissions. We evaluated a prototype implementation of IntentRepair on 869 Android open-source apps, showing that it is effective in automatically detecting and repairing information flow security bugs that originate in implicit intent-based communication, introducing only a modest overhead in terms of patch size.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel 等USENIX Security 2016 · 被引用 161 次
- GUIDER: GUI structure and vision co-guided test script repair for Android appsTongtong Xu, Minxue Pan, Yu Pei, Guiyin Li 等ISSTA 2021 · 被引用 30 次
- Towards Automatically Repairing Compatibility Issues in Published Android AppsYanjie Zhao, Li Li, Kui Liu, John C. GrundyICSE 2022 · 被引用 25 次
- Detecting and fixing data loss issues in Android appsWunan Guo, Zhen Dong, Liwei Shen, Wei Tian 等ISSTA 2022 · 被引用 17 次
- ConfFix: Repairing Configuration Compatibility Issues in Android AppsHuaxun Huang, Chi Xu, Ming Wen, Yepang Liu 等ISSTA 2023 · 被引用 10 次
相关 Paper
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 被引用 9 次
- MALintent: Coverage Guided Intent Fuzzing Framework for AndroidAmmar Askar, Fabian Fleischer, Christopher Kruegel, Giovanni Vigna 等NDSS 2025
- The Misuse of Android Unix Domain Sockets and Security ImplicationsYuru Shao, Jason Ott, Yunhan Jack Jia, Zhiyun Qian 等CCS 2016 · 被引用 41 次
- Keeping Secrets: Multi-objective Genetic Improvement for Detecting and Reducing Information LeakageIbrahim Mesecan, Daniel Blackwell, David Clark, Myra B. Cohen 等ASE 2022 · 被引用 5 次
- RAICC: Revealing Atypical Inter-Component Communication in Android AppsJordan Samhi, Alexandre Bartel, Tegawendé F. Bissyandé, Jacques KleinICSE 2021 · 被引用 3 次
