SEALANT: a detection and visualization tool for inter-app security vulnerabilities in Android
Abstract
Android's flexible communication model allows interactions among third-party apps, but it also leads to inter-app security vulnerabilities. Specifically, malicious apps can eavesdrop on interactions between other apps or exploit the functionality of those apps, which can expose a user's sensitive information to attackers. While the state-of-the-art tools have focused on detecting inter-app vulnerabilities in Android, they neither accurately analyze realistically large numbers of apps nor effectively deliver the identified issues to users. This paper presents SEALANT, a novel tool that combines static analysis and visualization techniques that, together, enable accurate identification of inter-app vulnerabilities as well as their systematic visualization. SEALANT statically analyzes architectural information of a given set of apps, infers vulnerable communication channels where inter-app attacks can be launched, and visualizes the identified information in a compositional representation. SEALANT has been demonstrated to accurately identify inter-app vulnerabilities from hundreds of real-world Android apps and to effectively deliver the identified information to users. (Demo Video: https://youtu.be/E4lLQonOdUw)
BibTeX
@inproceedings{Lee-al:ASE17,
author = {Youn Kyu Lee and
Peera Yoodee and
Arman Shahbazian and
Daye Nam and
Nenad Medvidovic},
title = {{SEALANT:} a detection and visualization tool for inter-app security vulnerabilities in Android},
booktitle = {ASE},
pages = {883--888},
publisher = {{IEEE} Computer Society},
year = {2017},
}