Highly Precise and Efficient Analysis of PendingIntent Vulnerabilities for Android Apps

被引:0
|
作者
Sarvazimi, Azadeh [1 ]
Sakhaei-Nia, Mehdi [1 ]
Bathaeian, Narges Sadat [1 ]
机构
[1] Department of Computer Engineering, Faculty of Engineering, Bu-Ali Sina University, Hamedan, Iran
关键词
Denial-of-service attack;
D O I
10.1155/2024/8663701
中图分类号
学科分类号
摘要
Te expanding development of android applications is partially due to the communication model, named inter-component communication (ICC) model. PendingIntent (PI) is a powerful feature that is used for ICC. Many android developers use PI in their apps, but if it is used insecurely, it can pose risks and result in diferent types of attacks like denial of service, privilege escalation, and data leakage. Hence, it is crucial to detect vulnerabilities related to PI before android apps are released on Android app stores. In this paper, a new PI-related vulnerability is introduced, which is detected by the proposed method in addition to the vulnerabilities pointed out in other methods. In addition, the proposed method that is based on static analysis takes less time than other methods to detect the vulnerabilities. For evaluation, we compare the proposed method with PIAnalyzer tool. Results on 51 application benchmarks show that the proposed method detects the new PI-related vulnerability that is not detected by PIAnalyzer. Also, the proposed method detects vulnerabilities 27% faster than PIAnalyzer. © 2024 Azadeh Sarvazimi et al.
引用
收藏
相关论文
共 50 条
  • [31] DroidRista: a highly precise static data flow analysis framework for android applications
    Alzaidi, Areej
    Alshehri, Suhair
    Buhari, Seyed M.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2020, 19 (05) : 523 - 536
  • [32] DroidRista: a highly precise static data flow analysis framework for android applications
    Areej Alzaidi
    Suhair Alshehri
    Seyed M. Buhari
    International Journal of Information Security, 2020, 19 : 523 - 536
  • [33] An efficient security testing mechanism for Android Apps based on malware analysis and optimized XGBoost
    Kumar, Pawan
    Singh, Sukhdip
    Suman
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (24) : 64767 - 64794
  • [34] Kunai: A static analysis framework for Android apps
    Blazquez, Eduardo
    Tapiador, Juan
    SOFTWAREX, 2023, 22
  • [35] Amandroid: A Precise and General Inter-component Data Flow Analysis Framework for Security Vetting of Android Apps
    Wei, Fengguo
    Roy, Sankardas
    Ou, Xinming
    Robby
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2018, 21 (03)
  • [36] Amandroid: A Precise and General Inter-component Data Flow Analysis Framework for Security Vetting of Android Apps
    Wei, Fengguo
    Roy, Sankardas
    Ou, Xinming
    Robby
    CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, : 1329 - 1341
  • [37] Is Mutation Analysis Effective at Testing Android Apps?
    Deng, Lin
    Offutt, Jeff
    Samudio, David
    2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS), 2017, : 86 - 93
  • [38] Vulnerability Analysis of Android Auto Infotainment Apps
    Mandal, Amit Kr
    Cortesi, Agostino
    Ferrara, Pietro
    Panarotto, Federica
    Spoto, Fausto
    2018 ACM INTERNATIONAL CONFERENCE ON COMPUTING FRONTIERS, 2018, : 183 - 190
  • [39] AndroidProtect: Android Apps Security Analysis System
    Zhang, Tong
    Li, Tao
    Wang, Hao
    Xiao, Zhijie
    COLLABORATE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, COLLABORATECOM 2016, 2017, 201 : 583 - 594
  • [40] A GUI-based Metamorphic Testing Technique for Detecting Authentication Vulnerabilities in Android Mobile Apps
    Amalfitano, Domenico
    Junior, Misael
    Fasolino, Anna Rita
    Delamaro, Marcio
    JOURNAL OF SYSTEMS AND SOFTWARE, 2025, 224