A central aspect of the Android platform is Inter-Component Communication (ICC), which allows the reuse of functionality across apps and components through message passing. While ICC is a powerful feature, it also presents a serious attack surface. This paper addresses the issue of generating exploits for a subset of Android ICC vulnerabilities (i.e., IDOS, XAS, and FI) using static analysis, Deep Reinforcement Learning-based dynamic analysis, and software instrumentation. Our approach, called RONIN, outperforms state-of-the-art and baseline tools in terms of the number of exploited vulnerabilities.

Assessing the security of inter-app communications in android through reinforcement learning

Merlo A;
2023-01-01

Abstract

A central aspect of the Android platform is Inter-Component Communication (ICC), which allows the reuse of functionality across apps and components through message passing. While ICC is a powerful feature, it also presents a serious attack surface. This paper addresses the issue of generating exploits for a subset of Android ICC vulnerabilities (i.e., IDOS, XAS, and FI) using static analysis, Deep Reinforcement Learning-based dynamic analysis, and software instrumentation. Our approach, called RONIN, outperforms state-of-the-art and baseline tools in terms of the number of exploited vulnerabilities.
2023
Security testing, Android, ICC Vulnerabilities, Software security engineering, Reinforcement learning
File in questo prodotto:
File Dimensione Formato  
1-s2.0-S0167404823002213-main.pdf

non disponibili

Tipologia: Versione Editoriale (PDF)
Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 2.44 MB
Formato Adobe PDF
2.44 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14252/1087
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
social impact