kirancodes.me
To Proof Maintenance & Beyond!

SEALANT: a detection and visualization tool for inter-app security vulnerabilities in Android

Youn Kyu Lee, Peera Yoodee, Arman Shahbazian, Daye Nam, Nenad Medvidovic

Abstract

Android's flexible communication model allows interactions among third-party apps, but it also leads to inter-app security vulnerabilities. Specifically, malicious apps can eavesdrop on interactions between other apps or exploit the functionality of those apps, which can expose a user's sensitive information to attackers. While the state-of-the-art tools have focused on detecting inter-app vulnerabilities in Android, they neither accurately analyze realistically large numbers of apps nor effectively deliver the identified issues to users. This paper presents SEALANT, a novel tool that combines static analysis and visualization techniques that, together, enable accurate identification of inter-app vulnerabilities as well as their systematic visualization. SEALANT statically analyzes architectural information of a given set of apps, infers vulnerable communication channels where inter-app attacks can be launched, and visualizes the identified information in a compositional representation. SEALANT has been demonstrated to accurately identify inter-app vulnerabilities from hundreds of real-world Android apps and to effectively deliver the identified information to users. (Demo Video: https://youtu.be/E4lLQonOdUw)

BibTeX
@inproceedings{Lee-al:ASE17,
  author    = {Youn Kyu Lee and
               Peera Yoodee and
               Arman Shahbazian and
               Daye Nam and
               Nenad Medvidovic},
  title     = {{SEALANT:} a detection and visualization tool for inter-app security vulnerabilities in Android},
  booktitle = {ASE},
  pages     = {883--888},
  publisher = {{IEEE} Computer Society},
  year      = {2017},
}

Related papers