Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Automatically Exploiting Potential Component Leaks in Android Applications
Li, Li; {"lastName":"BARTEL", "firstNames":"Alexandre","affiliations":["University of Luxembourg \u003e Interdisciplinary Centre for Security, Reliability and Trust (SNT)"]} 50024843; Klein, Jacques et al.
2014In The 13th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (IEEE TrustCom-14), IEEE, Sept. 2014, Beijing, China.
Peer reviewed
 

Files


Full Text
07011274.pdf
Author postprint (330.35 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Abstract :
[en] We present PCLeaks, a tool based on inter- component communication (ICC) vulnerabilities to perform data-flow analysis on Android applications to find potential component leaks that could potentially be exploited by other components. To evaluate our approach, we run PCLeaks on 2000 apps randomly selected from the Google Play store. PCLeaks reports 986 potential component leaks in 185 apps. For each leak reported by PCLeaks, PCLeaksValidator automatically generates an Android app which tries to exploit the leak. By manually running a subset of the generated apps, we find that 75% of the reported leaks are exploitable leaks.
Disciplines :
Computer science
Author, co-author :
Li, Li ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
{"lastName":"BARTEL", "firstNames":"Alexandre","affiliations":["University of Luxembourg \u003e Interdisciplinary Centre for Security, Reliability and Trust (SNT)"]} 50024843 
Klein, Jacques ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Le Traon, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Language :
English
Title :
Automatically Exploiting Potential Component Leaks in Android Applications
Publication date :
September 2014
Event name :
The 13th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (IEEE TrustCom-14)
Event date :
from 24-09-2014 to 26-09-2014
Main work title :
The 13th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (IEEE TrustCom-14), IEEE, Sept. 2014, Beijing, China.
Peer reviewed :
Peer reviewed
Funders :
FNR - Fonds National de la Recherche [LU]
Available on ORBilu :
since 02 February 2015

Statistics


Number of views
135 (12 by Unilu)
Number of downloads
357 (7 by Unilu)

Scopus citations®
 
45
Scopus citations®
without self-citations
38

Bibliography


Similar publications



Contact ORBilu