Statically Checking the Inconsistencies of Security Assumptions/Measures in Android Apps and Systems
A common reason that security problems arise is the lack of consistency in designing and implementing software, especially the system security mechanisms. This talk will cover three related pieces of work on analyzing inconsistencies in Android OS that lead to security flaws of apps and system services. Specifically, the inconsistencies are in the form of (1) offering inter-process communication (IPC) mechanisms with inconsistent (strong/weak) security guarantees; (2) failing to make sure all paths to protected operations are covered; (3) misplacing trust on code or data. Through statically analyzing a large number of apps and system services (from Google and third-party vendors), we identified dozens of vulnerabilities and most of them result in patches.
Tue 6 NovDisplayed time zone: Guadalajara, Mexico City, Monterrey change
13:30 - 15:00 | |||
13:30 30mTalk | Delphi: Connecting Researchers to Enable Comparable Large-Scale Experiments in Program Analysis NJR Ben Hermann University of Paderborn Media Attached File Attached | ||
14:00 30mTalk | Statically Checking the Inconsistencies of Security Assumptions/Measures in Android Apps and Systems NJR Zhiyun Qian UC Riverside | ||
14:30 30mTalk | Qualitas Corpus Analysis NJR Craig Anslow Victoria University of Wellington |