Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
Effective Inter-Component Communication Mapping in Android with Epicc: An Essential Step Towards Holistic Security Analysis
Octeau, Damien; McDaniel, Patrick; Jha, Somesh et al.
2013In Effective Inter-Component Communication Mapping in Android with Epicc: An Essential Step Towards Holistic Security Analysis
Peer reviewed
 

Documents


Texte intégral
Effective_Inter-Component_Communication_Mapping_in_Android_with_EPICC.pdf
Preprint Auteur (1.42 MB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Résumé :
[en] Many threats present in smartphones are the result of interactions between application components, not just artifacts of single components. However, current techniques for identifying inter-application communication are ad hoc and do not scale to large numbers of ap- plications. In this paper, we reduce the discovery of inter-component communication (ICC) in smartphones to an instance of the Interprocedural Distributive Environment (IDE) problem, and develop a sound static analysis technique targeted to the Android platform. We apply this analysis to 1,200 applications selected from the Play store and characterize the locations and substance of their ICC. Experiments show that full specifications for ICC can be identified for over 93% of ICC locations for the applications studied. Further the analysis scales well; analysis of each application took on average 113 seconds to complete. Epicc, the resulting tool, finds ICC vulnerabilities with far fewer false positives than the next best tool. In this way, we develop a scalable vehicle to extend current security analysis to entire collections of applications as well as the interfaces they export.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
Octeau, Damien
McDaniel, Patrick
Jha, Somesh
BARTEL, Alexandre ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Bodden, Eric
KLEIN, Jacques  ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
LE TRAON, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Langue du document :
Anglais
Titre :
Effective Inter-Component Communication Mapping in Android with Epicc: An Essential Step Towards Holistic Security Analysis
Date de publication/diffusion :
2013
Nom de la manifestation :
USENIX Security 2013
Date de la manifestation :
August 14-16 2013
Manifestation à portée :
International
Titre de l'ouvrage principal :
Effective Inter-Component Communication Mapping in Android with Epicc: An Essential Step Towards Holistic Security Analysis
Peer reviewed :
Peer reviewed
Disponible sur ORBilu :
depuis le 06 décembre 2013

Statistiques


Nombre de vues
672 (dont 6 Unilu)
Nombre de téléchargements
770 (dont 1 Unilu)

citations Scopus®
 
344
citations Scopus®
sans auto-citations
314

Bibliographie


Publications similaires



Contacter ORBilu