AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency Detection
Yousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang, Ninghui Li, Chen Tian
摘要
—The Android framework has raised increased security concerns with regards to its access control enforcement. Particularly, existing research efforts successfully demonstrate that framework security checks are not always consistent across app-accessible APIs. However, existing efforts fall short in addressing peculiarities that characterize the complex Android access control and the diversity introduced by the heavy vendor customization. In this paper, we develop a new analysis framework AceDroid that models Android access control in a path-sensitive manner and normalizes diverse checks to a canonical form. We applied our proposed modeling to perform inconsistency analysis for 12 images. Our tool proved to be quite effective, enabling to detect a significant number of inconsistencies introduced by various vendors and to suppress substantial false alarms. Through investigating the results, we uncovered high impact attacks enabling to write a key logger, send premium sms messages, bypass user restrictions, perform a major denial of services and other critical operations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- Precise Android API Protection Mapping Derivation and ReasoningYousra Aafer, Guanhong Tao, Jianjun Huang, Xiangyu Zhang 等CCS 2018 · 被引用 51 次
- SmartAxe: Detecting Cross-Chain Vulnerabilities in Bridge Smart Contracts via Fine-Grained Static AnalysisZeqin Liao, Yuhong Nan, Henglong Liang, Sicheng Hao 等FSE 2024 · 被引用 18 次
- Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOSLuke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu 等S&P 2020 · 被引用 10 次
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 被引用 9 次
- Dissecting Residual APIs in Custom Android ROMsZeinab El-Rewini, Yousra AaferCCS 2021 · 被引用 8 次
它引用的顶会 Paper5
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel 等USENIX Security 2016 · 被引用 161 次
- Kratos: Discovering Inconsistent Security Policy Enforcement in the Android FrameworkYuru Shao, Qi Alfred Chen, Zhuoqing Morley Mao, Jason Ott 等NDSS 2016 · 被引用 85 次
- Harvesting Inconsistent Security Configurations in Custom Android ROMs via Differential AnalysisYousra Aafer, Xiao Zhang, Wenliang DuUSENIX Security 2016 · 被引用 43 次
- Life after App Uninstallation: Are the Data Still Alive? Data Residue Attacks on AndroidXiao Zhang, Kailiang Ying, Yousra Aafer, Zhenshen Qiu 等NDSS 2016 · 被引用 34 次
- Android ION Hazard: the Curse of Customizable Memory Management SystemHang Zhang, Dongdong She, Zhiyun QianCCS 2016 · 被引用 21 次
相关 Paper
- Uncovering Cross-Context Inconsistent Access Control Enforcement in AndroidHao Zhou, Haoyu Wang, Xiapu Luo, Ting Chen 等NDSS 2022
- Ariadne: Navigating through the Labyrinth of Data-Driven Customization Inconsistencies in AndroidParjanya Vyas, Haseeb Ur Rehman Faheem, Yousra Aafer, N. AsokanUSENIX Security 2025
- Poirot: Probabilistically Recommending Protections for the Android FrameworkZeinab El-Rewini, Zhuo Zhang, Yousra AaferCCS 2022 · 被引用 6 次
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 被引用 1 次
- Bringing Balance to the Force: Dynamic Analysis of the Android Application FrameworkAbdallah Dawoud, Sven BugielNDSS 2021
