Lune

USENIX Security2023顶会

Auditing Framework APIs via Inferred App-side Security Specifications

Parjanya Vyas, Asim Waheed, Yousra Aafer, N. Asokan

出版方
2023年份
3顶会引用

摘要

In this work, we explore auditing access control implementations of Android private framework APIs by leveraging app-side security specifications. The seemingly straightforward auditing task faces significant challenges. It requires extracting unconventional security indicators and understanding their relevance to private framework APIs. More importantly, addressing these challenges requires relying on uncertain hints. We hence, introduce Bluebird, a security auditing platform for Android APIs, that mimics a human expert. Bluebird seamlessly fuses human-like understanding of app-side logic with statically-derived program semantics using probabilistic inference to detect access control gaps in private APIs. 1 Henceforth, we use the term "security specification" in a broad sense to refer to the security policy that can be inferred from access control enforcement or other sensitivity indicators, rather than to a formal, written, security specification in the traditional sense. 2 An app component or a UI block.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper3

问问它们各自怎么用它

它引用的顶会 Paper8

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖