{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T00:51:23Z","timestamp":1740099083059,"version":"3.37.3"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319766867"},{"type":"electronic","value":"9783319766874"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-76687-4_4","type":"book-chapter","created":{"date-parts":[[2018,2,23]],"date-time":"2018-02-23T04:02:09Z","timestamp":1519358529000},"page":"49-65","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Unraveling Reflection Induced Sensitive Leaks in Android Apps"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8223-5975","authenticated-orcid":false,"given":"Jyoti","family":"Gajrani","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vijay","family":"Laxmi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Meenakshi","family":"Tripathi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Manoj S.","family":"Gaur","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daya Ram","family":"Sharma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Akka","family":"Zemmari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohamed","family":"Mosbah","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,2,24]]},"reference":[{"key":"4_CR1","unstructured":"https:\/\/docs.oracle.com\/javase\/tutorial\/reflect\/"},{"key":"4_CR2","unstructured":"https:\/\/github.com\/pjlantz\/droidbox\/tree\/master\/APIMonitor"},{"key":"4_CR3","unstructured":"Androguard. https:\/\/github.com\/androguard\/androguard"},{"key":"4_CR4","unstructured":"DroidBench. https:\/\/github.com\/secure-software-engineering\/DroidBench\/tree\/develop"},{"key":"4_CR5","unstructured":"Intents and Intent Filters. https:\/\/developer.android.com\/guide\/components\/intents-filters.html"},{"key":"4_CR6","unstructured":"RobotiumTech\/robotium. https:\/\/github.com\/RobotiumTech"},{"key":"4_CR7","unstructured":"VirusShare. https:\/\/virusshare.com\/"},{"issue":"6","key":"4_CR8","doi-asserted-by":"crossref","first-page":"259","DOI":"10.1145\/2666356.2594299","volume":"49","author":"S Arzt","year":"2014","unstructured":"Arzt, S., Rasthofer, S., Fritz, C., Bodden, E., Bartel, A., Klein, J., Le Traon, Y., Octeau, D., McDaniel, P.: Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. ACM SIGPLAN Not. 49(6), 259\u2013269 (2014)","journal-title":"ACM SIGPLAN Not."},{"key":"4_CR9","doi-asserted-by":"crossref","unstructured":"Bodden, E., Sewe, A., Sinschek, J., Oueslati, H., Mezini, M.: Taming reflection: aiding static analysis in the presence of reflection and custom class loaders. In: Proceedings of the 33rd International Conference on Software Engineering, pp. 241\u2013250. ACM (2011)","DOI":"10.1145\/1985793.1985827"},{"key":"4_CR10","unstructured":"Elish, K.O., Yao, D., Ryder, B.G.: On the need of precise inter-app icc classification for detecting android malware collusions. In: Proceedings of IEEE Mobile Security Technologies (MoST), in Conjunction with the IEEE Symposium on Security and Privacy (2015)"},{"key":"4_CR11","doi-asserted-by":"crossref","unstructured":"Feng, Y., Anand, S., Dillig, I., Aiken, A.: Apposcopy: semantics-based detection of android malware through static analysis. In: Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering, pp. 576\u2013587. ACM (2014)","DOI":"10.1145\/2635868.2635869"},{"key":"4_CR12","doi-asserted-by":"crossref","unstructured":"Gajrani, J., Li, L., Laxmi, V., Tripathi, M., Gaur, M.S., Conti, M.: Poster: detection of information leaks via reflection in android apps. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 911\u2013913. ACM (2017)","DOI":"10.1145\/3052973.3055162"},{"key":"4_CR13","doi-asserted-by":"crossref","unstructured":"Gajrani, J., Tripathi, M., Laxmi, V., Gaur, M., Conti, M., Rajarajan, M.: Spectra: a precise framework for analyzing cryptographic vulnerabilities in android apps. In: 2017 14th IEEE Annual Consumer Communications & Networking Conference (CCNC), pp. 854\u2013860. IEEE (2017)","DOI":"10.1109\/CCNC.2017.7983245"},{"key":"4_CR14","doi-asserted-by":"crossref","unstructured":"Gordon, M.I., Kim, D., Perkins, J.H., Gilham, L., Nguyen, N., Rinard, M.C.: Information flow analysis of android applications in droidsafe. In: NDSS. Citeseer (2015)","DOI":"10.14722\/ndss.2015.23089"},{"key":"4_CR15","unstructured":"Lam, P., Bodden, E., Lhot\u00e1k, O., Hendren, L.: The soot framework for java program analysis: a retrospective. In: Cetus Users and Compiler Infastructure Workshop (CETUS 2011), vol. 15, p. 35 (2011)"},{"key":"4_CR16","doi-asserted-by":"crossref","unstructured":"Li, L., Bartel, A., Bissyande, T.F., Klein, J., Le Traon, Y., Arzt, S., Rasthofer, S., Bodden, E., Octeau, D., McDaniel, P.: IccTA: Detecting inter-component privacy leaks in android apps. In: Proceedings of the 37th International Conference on Software Engineering, vol. 1, pp. 280\u2013291. IEEE Press (2015)","DOI":"10.1109\/ICSE.2015.48"},{"key":"4_CR17","doi-asserted-by":"crossref","unstructured":"Li, L., Bissyand\u00e9, T.F., Octeau, D., Klein, J.: Droidra: taming reflection to support whole-program analysis of android apps. In: Proceedings of the 25th International Symposium on Software Testing and Analysis, pp. 318\u2013329. ACM (2016)","DOI":"10.1145\/2931037.2931044"},{"key":"4_CR18","doi-asserted-by":"crossref","unstructured":"Lindorfer, M., Neugschwandtner, M., Weichselbaum, L., Fratantonio, Y., Van Der Veen, V., Platzer, C.: Andrubis-1,000,000 apps later: a view on current android malware behaviors. In: 2014 Third International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS), pp. 3\u201317. IEEE (2014)","DOI":"10.1109\/BADGERS.2014.7"},{"issue":"11","key":"4_CR19","doi-asserted-by":"crossref","first-page":"999","DOI":"10.1109\/TSE.2016.2550446","volume":"42","author":"D Octeau","year":"2016","unstructured":"Octeau, D., Luchaup, D., Jha, S., McDaniel, P.: Composite constant propagation and its application to android program analysis. IEEE Trans. Softw. Eng. 42(11), 999\u20131014 (2016)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"4_CR20","unstructured":"Octeau, D., McDaniel, P., Jha, S., Bartel, A., Bodden, E., Klein, J., Le Traon, Y.: Effective inter-component communication mapping in android: an essential step towards holistic security analysis. In: Presented as part of the 22nd USENIX Security Symposium (USENIX Security 2013), pp. 543\u2013558 (2013)"},{"key":"4_CR21","doi-asserted-by":"crossref","unstructured":"Rasthofer, S., Arzt, S., Miltenberger, M., Bodden, E.: Harvesting runtime values in android applications that feature anti-analysis techniques. In: Proceedings of the Annual Symposium on Network and Distributed System Security (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23066"},{"key":"4_CR22","doi-asserted-by":"crossref","unstructured":"Reps, T., Horwitz, S., Sagiv, M.: Precise interprocedural dataflow analysis via graph reachability. In: Proceedings of the 22nd ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, pp. 49\u201361. ACM (1995)","DOI":"10.1145\/199448.199462"},{"issue":"8","key":"4_CR23","doi-asserted-by":"crossref","first-page":"1294","DOI":"10.1109\/TIFS.2013.2267798","volume":"8","author":"BP Rocha","year":"2013","unstructured":"Rocha, B.P., Conti, M., Etalle, S., Crispo, B.: Hybrid static-runtime information flow and declassification enforcement. IEEE Trans. Inf. Forensics Secur. 8(8), 1294\u20131305 (2013)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"4_CR24","doi-asserted-by":"crossref","unstructured":"Rubinov, K., Rosculete, L., Mitra, T., Roychoudhury, A.: Automated partitioning of android applications for trusted execution environments. In: Proceedings of the 38th International Conference on Software Engineering, pp. 923\u2013934. ACM (2016)","DOI":"10.1145\/2884781.2884817"},{"key":"4_CR25","doi-asserted-by":"crossref","unstructured":"Wei, F., Roy, S., Ou, X., et al.: Amandroid: a precise and general inter-component data flow analysis framework for security vetting of android apps. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, pp. 1329\u20131341. ACM (2014)","DOI":"10.1145\/2660267.2660357"},{"key":"4_CR26","doi-asserted-by":"crossref","unstructured":"Wong, M.Y., Lie, D.: Intellidroid: a targeted input generator for the dynamic analysis of android malware. In: Proceedings of the Annual Symposium on Network and Distributed System Security (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23118"},{"key":"4_CR27","doi-asserted-by":"crossref","unstructured":"Zhang, M., Duan, Y., Feng, Q., Yin, H.: Towards automatic generation of security-centric descriptions for android apps. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 518\u2013529. ACM (2015)","DOI":"10.1145\/2810103.2813669"},{"key":"4_CR28","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Tan, T., Li, Y., Xue, J.: Ripple: reflection analysis for android apps in incomplete information environments. In: Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy, pp. 281\u2013288. ACM (2017)","DOI":"10.1145\/3029806.3029814"},{"key":"4_CR29","doi-asserted-by":"crossref","unstructured":"Zhauniarovich, Y., Ahmad, M., Gadyatskaya, O., Crispo, B., Massacci, F.: Stadyna: addressing the problem of dynamic code updates in the security analysis of android applications. In: Proceedings of the 5th ACM Conference on Data and Application Security and Privacy, pp. 37\u201348. ACM (2015)","DOI":"10.1145\/2699026.2699105"}],"container-title":["Lecture Notes in Computer Science","Risks and Security of Internet and Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-76687-4_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,11]],"date-time":"2019-10-11T13:36:49Z","timestamp":1570801009000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-76687-4_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319766867","9783319766874"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-76687-4_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2018]]}}}