Checking conformance of applications against GUI policies

Checking conformance of applications against GUI policies
复制标题

DOI:
10.1145/3468264.3468561
复制
发表时间:
2021-08
期刊:
Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering
影响因子:
--
通讯作者:
Zhen Zhang;Yu Feng;Michael D. Ernst;Sebastian Porst;Işıl Dillig
Zhen Zhang;Yu Feng;Michael D. Ernst;Sebastian Porst;Işıl Dillig
中科院分区:
其他
文献类型:
--
作者:
Zhen Zhang;Yu Feng;Michael D. Ernst;Sebastian Porst;Işıl Dillig

文献摘要

被引文献

相似文献

良好的图形用户界面(GUI)对于应用程序的可用性至关重要,因此供应商和监管机构越来越多地对GUI元素的外观以及与用户进行交互的方式越来越多地限制。出于这种关注,本文提出了一种新技术(基于静态分析),用于检查以正式规范语言表达的(Android)应用程序和GUI策略之间的符合性。特别是,本文(1)描述了一种用于形式化GUI政策的规范语言,(2)提出了一个新的程序抽象,称为_Event驱动的布局forest_,(3)描述了用于构建此抽象的静态分析,并针对A进行检查GUI政策。我们已经在一种名为Venus的工具中实施了拟议的方法,并在2361 Android应用程序和17个政策上对其进行了评估。我们的评估表明,金星可以发现执行广告欺诈的恶意应用,并确定对GUI设计指南和GDPR法律的违规行为。
A good graphical user interface (GUI) is crucial for an application's usability, so vendors and regulatory agencies increasingly place restrictions on how GUI elements should appear to and interact with users. Motivated by this concern, this paper presents a new technique (based on static analysis) for checking conformance between (Android) applications and GUI policies expressed in a formal specification language. In particular, this paper (1) describes a specification language for formalizing GUI policies, (2) proposes a new program abstraction called an _event-driven layout forest_, and (3) describes a static analysis for constructing this abstraction and checking it against a GUI policy. We have implemented the proposed approach in a tool called Venus, and we evaluate it on 2361 Android applications and 17 policies. Our evaluation shows that Venus can uncover malicious applications that perform ad fraud and identify violations of GUI design guidelines and GDPR laws.