DocFlow: Extracting Taint Specifications from Software Documentation

DocFlow: Extracting Taint Specifications from Software Documentation
复制标题

DocFlow:从软件文档中提取污点规范

DOI:
10.1145/3597503.3623312
复制
发表时间:
2024
期刊:
--
影响因子:
--
通讯作者:
Tileria M
Tileria M
中科院分区:
--
文献类型:
--
作者:
Tileria M

文献摘要

参考文献

相似文献

安全从业人员通常使用静态分析来检测 Android 应用程序中的安全问题和隐私侵犯。这些分析的合理性取决于平台的建模方式和敏感方法列表。考虑到可用方法的数量、Android 平台的更新速度以及 Google 在每个新版本上发布的专有库,收集这些方法通常变得不切实际。尽管 Android 平台在不断发展,但应用程序开发人员仍可以借助每个新 Android 版本附带的文档来应对所有这些新功能。在这项工作中,我们利用 Android 等平台提供的丰富文档,并提出了 DocFlow,这是一个直接从文档生成平台污点规范的框架。 DocFlow 使用 API 方法的文档对 API 方法的语义进行建模,以检测敏感方法(源和接收器)并为其分配语义标签。我们的方法不需要访问源代码,从而可以分析代码不可用的专有库。我们使用 Android 平台包和闭源 Google Play 服务库来评估 DocFlow。我们的结果表明,我们的框架能够高精度检测敏感方法,适应新的 API 版本,并且可以轻松扩展以检测其他方法类型。我们的方法提供了证据,证明 Android 文档编码了丰富的语义信息来对敏感方法进行分类,从而无需分析源代码或执行特征提取。
Security practitioners routinely use static analysis to detect security problems and privacy violations in Android apps. The soundness of these analyses depends on how the platform is modelled and the list of sensitive methods. Collecting these methods often becomes impractical given the number of methods available, the pace at which the Android platform is updated, and the proprietary libraries Google releases on each new version. Despite the constant evolution of the Android platform, app developers cope with all these new features thanks to the documentation that comes with each new Android release. In this work, we take advantage of the rich documentation provided by platforms like Android and propose DocFlow, a framework to generate taint specifications for a platform, directly from its documentation. DocFlow models the semantics of API methods using their documentation to detect sensitive methods (sources and sinks) and assigns them semantic labels. Our approach does not require access to source code, enabling the analysis of proprietary libraries for which the code is unavailable. We evaluate DocFlow using Android platform packages and closed-source Google Play Services libraries. Our results show that our framework detects sensitive methods with high precision, adapts to new API versions, and can be easily extended to detect other method types. Our approach provides evidence that Android documentation encodes rich semantic information to categorise sensitive methods, removing the need to analyse source code or perform feature extraction.
DOI: 10.1109/icse-seip52600.2021.00040
发表时间: 2021-05
期刊: 2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP)
影响因子: --
作者:
Pei Liu;Li Li-Li;Yichun Yan;M. Fazzini;J. Grundy
通讯作者: Pei Liu;Li Li-Li;Yichun Yan;M. Fazzini;J. Grundy
DOI: 10.1145/3314221.3314640
发表时间: 2019-06
期刊: Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation
影响因子: --
作者:
Jan Eberhardt;Samuel Steffen;Veselin Raychev;Martin T. Vechev
通讯作者: Jan Eberhardt;Samuel Steffen;Veselin Raychev;Martin T. Vechev
DOI: 10.1145/3560815
发表时间: 2023-09-01
影响因子: 16.6
作者:
Liu, Pengfei;Yuan, Weizhe;Neubig, Graham
通讯作者: Neubig, Graham
DOI: --
发表时间: 2013-05
期刊: --
影响因子: --
作者:
Steven Arzt;Siegfried Rasthofer;E. Bodden
通讯作者: Steven Arzt;Siegfried Rasthofer;E. Bodden
Flexeme:使用词汇流理清提交
DOI: 10.1145/3368089.3409693
发表时间: 2020
期刊: --
影响因子: --
作者:
Pâr?achi P
通讯作者: Pâr?achi P