Tainting-Assisted and Context-Migrated Symbolic Execution of Android Framework for Vulnerability Discovery and Exploit Generation

Tainting-Assisted and Context-Migrated Symbolic Execution of Android Framework for Vulnerability Discovery and Exploit Generation
复制标题

用于漏洞发现和利用生成的 Android 框架的污染辅助和上下文迁移符号执行

DOI:
10.1109/tmc.2019.2936561
复制
发表时间:
2020-12
影响因子:
7.9
通讯作者:
Liu Peng
Liu Peng
中科院分区:
计算机科学2区
文献类型:
--
作者:
Luo Lannan;Zeng Qiang;Cao Chen;Chen Kai;Liu Jian;Liu Limin;Gao Neng;Yang Min;Xing Xinyu;Liu Peng

文献摘要

参考文献

相似文献

Android应用程序框架是Android系统的组成部分和基础部分。 20亿个(截至2017年)Android设备中的每一个都依赖于Android框架的系统服务来管理应用程序和系统资源。给予批评家
Android Application Framework is an integral and foundational part of the Android system. Each of the two billion (as of 2017) Android devices relies on the system services of Android Framework to manage applications and system resources. Given its critical role, a vulnerability in the framework can be exploited to launch large-scale cyber attacks and cause severe harms to user security and privacy. Recently, many vulnerabilities in Android Framework were exposed, showing that it is indeed vulnerable and exploitable. While there is a large body of studies on Android application analysis, research on Android Framework analysis is very limited. In particular, to our knowledge, there is no prior work that investigates how to enable symbolic execution of the framework, an approach that has proven to be very powerful for vulnerability discovery and exploit generation. We design and build the first system, Centaur, that enables symbolic execution of Android Framework. Due to the middleware nature and technical peculiarities of the framework that impinge on the analysis, many unique challenges arise and are addressed in Centaur. The system has been applied to discovering new vulnerability instances, which can be exploited by recently uncovered attacks against the framework, and to generating PoC exploits.
DOI: --
发表时间: 2015-08
期刊: --
影响因子: --
作者:
David A. Ramos;D. Engler
通讯作者: David A. Ramos;D. Engler
DOI: 10.1007/s10515-013-0122-2
发表时间: 2013-09-01
影响因子: 3.4
作者:
Pasareanu, Corina S.;Visser, Willem;Rungta, Neha
通讯作者: Rungta, Neha
DOI: 10.1145/2976749.2978342
发表时间: 2016-10
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Kai Wang;Yuqing Zhang;Peng Liu
通讯作者: Kai Wang;Yuqing Zhang;Peng Liu
DOI: --
发表时间: 2015-08
期刊: --
影响因子: --
作者:
Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu
通讯作者: Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu
DOI: 10.14722/ndss.2015.23140
发表时间: 2015
期刊: --
影响因子: --
作者:
Yinzhi Cao;Y. Fratantonio;Antonio Bianchi;Manuel Egele;Christopher Krügel;Giovanni Vigna;Yan Chen
通讯作者: Yinzhi Cao;Y. Fratantonio;Antonio Bianchi;Manuel Egele;Christopher Krügel;Giovanni Vigna;Yan Chen