Highly Precise and Efficient Analysis of PendingIntent Vulnerabilities for Android Apps

被引:0
|
作者
Sarvazimi, Azadeh [1 ]
Sakhaei-Nia, Mehdi [1 ]
Bathaeian, Narges Sadat [1 ]
机构
[1] Department of Computer Engineering, Faculty of Engineering, Bu-Ali Sina University, Hamedan, Iran
关键词
Denial-of-service attack;
D O I
10.1155/2024/8663701
中图分类号
学科分类号
摘要
Te expanding development of android applications is partially due to the communication model, named inter-component communication (ICC) model. PendingIntent (PI) is a powerful feature that is used for ICC. Many android developers use PI in their apps, but if it is used insecurely, it can pose risks and result in diferent types of attacks like denial of service, privilege escalation, and data leakage. Hence, it is crucial to detect vulnerabilities related to PI before android apps are released on Android app stores. In this paper, a new PI-related vulnerability is introduced, which is detected by the proposed method in addition to the vulnerabilities pointed out in other methods. In addition, the proposed method that is based on static analysis takes less time than other methods to detect the vulnerabilities. For evaluation, we compare the proposed method with PIAnalyzer tool. Results on 51 application benchmarks show that the proposed method detects the new PI-related vulnerability that is not detected by PIAnalyzer. Also, the proposed method detects vulnerabilities 27% faster than PIAnalyzer. © 2024 Azadeh Sarvazimi et al.
引用
收藏
相关论文
共 50 条
  • [41] API Change Impact Analysis for Android Apps
    Mahmud, Tarek
    Khan, Mujahid
    Rouijel, Jihan
    Che, Meiru
    Yang, Guowei
    2021 IEEE 45TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2021), 2021, : 894 - 903
  • [42] An Efficient, Robust, and Scalable Approach for Analyzing Interacting Android Apps
    Tsutano, Yutaka
    Bachala, Shakthi
    Srisa-an, Witawas
    Rothermel, Gregg
    Dinh, Jackson
    2017 IEEE/ACM 39TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE), 2017, : 324 - 334
  • [43] Security Apps under the Looking Glass: An Empirical Analysis of Android Security Apps
    Yao, Weixian
    Li, Yexuan
    Lin, Weiye
    Hu, Tianhui
    Chowdhury, Imran
    Masood, Rahat
    Seneviratne, Suranga
    PROCEEDINGS OF THE 2020 IEEE 45TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2020), 2020, : 381 - 384
  • [44] FlowDroid: Precise Context, Flow, Field, Object-sensitive and Lifecycle-aware Taint Analysis for Android Apps
    Arzt, Steven
    Rasthofer, Siegfried
    Fritz, Christian
    Bodden, Eric
    Bartel, Alexandre
    Klein, Jacques
    Le Traon, Yves
    Octeau, Damien
    McDaniel, Patrick
    ACM SIGPLAN NOTICES, 2014, 49 (06) : 259 - 269
  • [45] Method to Modify the Hex of Android Manifest File in Android Apps for Dynamic Analysis
    Lee, Suhyoo
    Park, Junhoo
    Ryou, Jaecheol
    ADVANCES IN COMPUTER SCIENCE AND UBIQUITOUS COMPUTING, 2018, 474 : 784 - 789
  • [46] Detecting Software Vulnerabilities in Android Using Static Analysis
    Dhaya, R.
    Poongodi, M.
    2014 INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION CONTROL AND COMPUTING TECHNOLOGIES (ICACCCT), 2014, : 915 - 918
  • [47] Privacy Analysis of Android Apps: Implicit Flows and Quantitative Analysis
    Barbon, Gianluca
    Cortesi, Agostino
    Ferrara, Pietro
    Pistoia, Marco
    Tripp, Omer
    COMPUTER INFORMATION SYSTEMS AND INDUSTRIAL MANAGEMENT, 2015, 9339 : 3 - 23
  • [48] Systematic Analysis and Detection of Misconfiguration Vulnerabilities in Android Smartphones
    Han, Zhihui
    Cheng, Liang
    Zhang, Yang
    Zeng, Shuke
    Deng, Yi
    Sun, Xiaoshan
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 432 - 439
  • [49] FIRMSCOPE: Automatic Uncovering of Privilege-Escalation Vulnerabilities in Pre-Installed Apps in Android Firmware
    Elsabagh, Mohamed
    Johnson, Ryan
    Stavrou, Angelos
    Zuo, Chaoshun
    Zhao, Qingchuan
    Lin, Zhiqiang
    PROCEEDINGS OF THE 29TH USENIX SECURITY SYMPOSIUM, 2020, : 2379 - 2396
  • [50] Poster: Efficient and Deterministic Replay for Web-enabled Android Apps
    Yan, Fangge
    Qi, Zhengwei
    Xia, Mingyuan
    Liu, Xue
    PROCEEDINGS 2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING - COMPANION (ICSE-COMPANION, 2018, : 329 - 330