{"id":"https://openalex.org/W2047650489","doi":"https://doi.org/10.1147/jrd.2013.2284403","title":"Automatic detection of inter-application permission leaks in Android applications","display_name":"Automatic detection of inter-application permission leaks in Android applications","publication_year":2013,"publication_date":"2013-11-01","ids":{"openalex":"https://openalex.org/W2047650489","doi":"https://doi.org/10.1147/jrd.2013.2284403","mag":"2047650489"},"language":"en","primary_location":{"id":"doi:10.1147/jrd.2013.2284403","is_oa":false,"landing_page_url":"https://doi.org/10.1147/jrd.2013.2284403","pdf_url":null,"source":{"id":"https://openalex.org/S4210219925","display_name":"IBM Journal of Research and Development","issn_l":"0018-8646","issn":["0018-8646","2151-8556"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320652","host_organization_name":"IBM","host_organization_lineage":["https://openalex.org/P4310320652"],"host_organization_lineage_names":["IBM"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IBM Journal of Research and Development","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5002814285","display_name":"Drago\u015f Sb\u00eerlea","orcid":null},"institutions":[{"id":"https://openalex.org/I74775410","display_name":"Rice University","ror":"https://ror.org/008zs3103","country_code":"US","type":"education","lineage":["https://openalex.org/I74775410"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"D. Sbirlea","raw_affiliation_strings":["Department of Computer Science, Rice University, Houston, TX, USA","Department of Computer Science Rice University Houston, TX"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Rice University, Houston, TX, USA","institution_ids":["https://openalex.org/I74775410"]},{"raw_affiliation_string":"Department of Computer Science Rice University Houston, TX","institution_ids":["https://openalex.org/I74775410"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5059032849","display_name":"Michael Burke","orcid":"https://orcid.org/0000-0001-7426-1498"},"institutions":[{"id":"https://openalex.org/I74775410","display_name":"Rice University","ror":"https://ror.org/008zs3103","country_code":"US","type":"education","lineage":["https://openalex.org/I74775410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"M. G. Burke","raw_affiliation_strings":["Department of Computer Science, Rice University, Houston , TX, USA","Department of Computer Science Rice University Houston, TX"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Rice University, Houston , TX, USA","institution_ids":["https://openalex.org/I74775410"]},{"raw_affiliation_string":"Department of Computer Science Rice University Houston, TX","institution_ids":["https://openalex.org/I74775410"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072393047","display_name":"Salvatore Guarnieri","orcid":null},"institutions":[{"id":"https://openalex.org/I4210106712","display_name":"Alliance for Safe Kids","ror":"https://ror.org/01922pt58","country_code":"US","type":"nonprofit","lineage":["https://openalex.org/I4210106712"]},{"id":"https://openalex.org/I1341412227","display_name":"IBM (United States)","ror":"https://ror.org/05hh8d621","country_code":"US","type":"company","lineage":["https://openalex.org/I1341412227"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"S. Guarnieri","raw_affiliation_strings":["IBM Software Group, Yorktown Heights, NY, USA","IBM Software Group, Yorktown Heights, NY#TAB#"],"affiliations":[{"raw_affiliation_string":"IBM Software Group, Yorktown Heights, NY, USA","institution_ids":["https://openalex.org/I1341412227","https://openalex.org/I4210106712"]},{"raw_affiliation_string":"IBM Software Group, Yorktown Heights, NY#TAB#","institution_ids":["https://openalex.org/I1341412227"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066501364","display_name":"Marco Pistoia","orcid":"https://orcid.org/0000-0001-9002-1128"},"institutions":[{"id":"https://openalex.org/I1341412227","display_name":"IBM (United States)","ror":"https://ror.org/05hh8d621","country_code":"US","type":"company","lineage":["https://openalex.org/I1341412227"]},{"id":"https://openalex.org/I4210114115","display_name":"IBM Research - Thomas J. Watson Research Center","ror":"https://ror.org/0265w5591","country_code":"US","type":"facility","lineage":["https://openalex.org/I1341412227","https://openalex.org/I4210114115"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"M. Pistoia","raw_affiliation_strings":["IBM Research Division, Thomas J. Watson Research Center, Yorktown Heights, NY, USA","IBM Research, Division Thomas J. Watson Research Center, Yorktown Heights, NY#TAB#"],"affiliations":[{"raw_affiliation_string":"IBM Research Division, Thomas J. Watson Research Center, Yorktown Heights, NY, USA","institution_ids":["https://openalex.org/I4210114115"]},{"raw_affiliation_string":"IBM Research, Division Thomas J. Watson Research Center, Yorktown Heights, NY#TAB#","institution_ids":["https://openalex.org/I1341412227"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5043513001","display_name":"Vivek Sarkar","orcid":"https://orcid.org/0000-0002-3433-8830"},"institutions":[{"id":"https://openalex.org/I74775410","display_name":"Rice University","ror":"https://ror.org/008zs3103","country_code":"US","type":"education","lineage":["https://openalex.org/I74775410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"V. Sarkar","raw_affiliation_strings":["Department of Computer Science, Rice University, Houston , TX, USA","Department of Computer Science Rice University Houston, TX"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Rice University, Houston , TX, USA","institution_ids":["https://openalex.org/I74775410"]},{"raw_affiliation_string":"Department of Computer Science Rice University Houston, TX","institution_ids":["https://openalex.org/I74775410"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5002814285"],"corresponding_institution_ids":["https://openalex.org/I74775410"],"apc_list":null,"apc_paid":null,"fwci":7.3418,"has_fulltext":false,"cited_by_count":82,"citation_normalized_percentile":{"value":0.97692398,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":100},"biblio":{"volume":"57","issue":"6","first_page":"10:1","last_page":"10:12"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9970999956130981,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/permission","display_name":"Permission","score":0.9735231995582581},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8010498285293579},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.7824336290359497},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5966672897338867},{"id":"https://openalex.org/keywords/java","display_name":"Java","score":0.4617280066013336},{"id":"https://openalex.org/keywords/taint-checking","display_name":"Taint checking","score":0.4337666630744934},{"id":"https://openalex.org/keywords/application-programming-interface","display_name":"Application programming interface","score":0.43127819895744324},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.3558026850223541},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.22060632705688477}],"concepts":[{"id":"https://openalex.org/C2779089604","wikidata":"https://www.wikidata.org/wiki/Q7169333","display_name":"Permission","level":2,"score":0.9735231995582581},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8010498285293579},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.7824336290359497},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5966672897338867},{"id":"https://openalex.org/C548217200","wikidata":"https://www.wikidata.org/wiki/Q251","display_name":"Java","level":2,"score":0.4617280066013336},{"id":"https://openalex.org/C63116202","wikidata":"https://www.wikidata.org/wiki/Q7676227","display_name":"Taint checking","level":3,"score":0.4337666630744934},{"id":"https://openalex.org/C99613125","wikidata":"https://www.wikidata.org/wiki/Q165194","display_name":"Application programming interface","level":2,"score":0.43127819895744324},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.3558026850223541},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.22060632705688477},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1147/jrd.2013.2284403","is_oa":false,"landing_page_url":"https://doi.org/10.1147/jrd.2013.2284403","pdf_url":null,"source":{"id":"https://openalex.org/S4210219925","display_name":"IBM Journal of Research and Development","issn_l":"0018-8646","issn":["0018-8646","2151-8556"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320652","host_organization_name":"IBM","host_organization_lineage":["https://openalex.org/P4310320652"],"host_organization_lineage_names":["IBM"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IBM Journal of Research and Development","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W1614825945","https://openalex.org/W1917620371","https://openalex.org/W1963971515","https://openalex.org/W1972796262","https://openalex.org/W1988036170","https://openalex.org/W1994588724","https://openalex.org/W2061603028","https://openalex.org/W2094245295","https://openalex.org/W2101834106","https://openalex.org/W2114275288","https://openalex.org/W2122440889","https://openalex.org/W2140095007","https://openalex.org/W2153497135","https://openalex.org/W2153542583","https://openalex.org/W2158888459","https://openalex.org/W2398484989"],"related_works":["https://openalex.org/W2316685381","https://openalex.org/W3003485427","https://openalex.org/W2056388267","https://openalex.org/W2249350383","https://openalex.org/W2755037920","https://openalex.org/W4210309948","https://openalex.org/W4388923452","https://openalex.org/W2072937473","https://openalex.org/W3211901564","https://openalex.org/W2786416059"],"abstract_inverted_index":{"The":[0],"Android\u00ae":[1],"operating":[2],"system":[3],"builds":[4],"upon":[5],"already":[6],"well-established":[7],"permission":[8,68,138,215],"systems":[9],"but":[10],"complements":[11],"them":[12],"by":[13,166],"allowing":[14],"application":[15,46,76,130],"components":[16],"to":[17,48,54,78,137,144,227],"be":[18,82,145,224],"reused":[19],"within":[20],"and":[21,70,103,140,231],"across":[22],"applications":[23,183,193],"through":[24],"a":[25,94,114,157],"single":[26],"communication":[27],"mechanism,":[28],"called":[29],"the":[30,100,188,200,211,220,228,241],"Intent":[31,71],"mechanism.":[32],"In":[33],"this":[34,89,151],"paper,":[35],"we":[36,40,91,112,153,217],"describe":[37],"techniques":[38],"that":[39,50,75,161,185,219,235],"developed":[41,92,113,154],"for":[42,96,117,174],"statically":[43],"detecting":[44],"Android":[45,106,175,192,229],"vulnerability":[47,77],"attacks":[49,80],"obtain":[51],"unauthorized":[52],"access":[53],"permission-protected":[55,121],"information.":[56],"We":[57,73],"address":[58],"three":[59],"kinds":[60],"of":[61,105,120,147,159,171,181,187,213],"such":[62,172],"attacks,":[63],"known":[64],"as":[65],"confused":[66],"deputy,":[67],"collusion,":[69],"spoofing.":[72],"show":[74],"these":[79,142],"can":[81],"detected":[83],"using":[84],"taint":[85],"analysis.":[86],"Based":[87,149],"on":[88,150,163],"technique,":[90],"PermissionFlow,":[93],"tool":[95],"discovering":[97],"vulnerabilities":[98],"in":[99,124,240],"byte":[101],"code":[102],"configuration":[104],"applications.":[107],"To":[108],"enable":[109],"PermissionFlow":[110,160,203],"analysis,":[111],"static":[115],"technique":[116,128],"automatic":[118,169],"identification":[119,170],"information":[122,197],"sources":[123,146],"permission-based":[125],"systems.":[126],"This":[127],"identifies":[129],"programming":[131],"interfaces":[132],"(APIs)":[133],"whose":[134],"execution":[135],"leads":[136],"checking":[139],"considers":[141],"APIs":[143,173],"taint.":[148],"approach,":[152],"Permission":[155],"Mapper,":[156],"component":[158],"improves":[162],"previous":[164],"work":[165],"performing":[167],"fully":[168],"Java\u00ae":[176],"code.":[177],"Our":[178],"automated":[179],"analysis":[180,222],"popular":[182,190],"found":[184,204],"56%":[186],"most":[189],"313":[191],"actively":[194],"use":[195,237],"intercomponent":[196],"flows.":[198],"Among":[199],"tested":[201],"applications,":[202],"four":[205],"exploitable":[206],"vulnerabilities.":[207],"By":[208],"helping":[209],"ensure":[210],"absence":[212],"inter-application":[214],"leaks,":[216],"believe":[218],"proposed":[221],"will":[223],"highly":[225],"beneficial":[226],"ecosystem":[230],"other":[232],"mobile":[233],"platforms":[234],"may":[236],"similar":[238],"analyses":[239],"future.":[242]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":6},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":11},{"year":2019,"cited_by_count":9},{"year":2018,"cited_by_count":13},{"year":2017,"cited_by_count":15},{"year":2016,"cited_by_count":9},{"year":2015,"cited_by_count":11},{"year":2014,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
