Abstract
We present PCLeaks, a tool based on inter-component communication (ICC) vulnerabilities to perform data-flow analysis on Android applications to find potential component leaks that could potentially be exploited by other components. To evaluate our approach, we run PCLeaks on 2000 apps randomly selected from the Google Play store. PCLeaks reports 986 potential component leaks in 185 apps. For each leak reported by PCLeaks, PCLeaksValidator automatically generates an Android app which tries to exploit the leak. By manually running a subset of the generated apps, we find that 75% of the reported leaks are exploitable leaks.
Original language | English |
---|---|
Title of host publication | Proceedings - 2014 IEEE 13th International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2014 |
Editors | Yunhao Liu, Nei Kato, Keqiu Li, Jian Ren |
Place of Publication | Piscataway NJ USA |
Publisher | IEEE, Institute of Electrical and Electronics Engineers |
Pages | 388-397 |
Number of pages | 10 |
ISBN (Electronic) | 9781479965137 |
DOIs | |
Publication status | Published - 2014 |
Externally published | Yes |
Event | IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) 2014 - Beijing, China Duration: 24 Sept 2014 → 26 Sept 2014 Conference number: 13th |
Conference
Conference | IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) 2014 |
---|---|
Abbreviated title | TrustCom 2014 |
Country/Territory | China |
City | Beijing |
Period | 24/09/14 → 26/09/14 |