{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2023,9,3]],"date-time":"2023-09-03T10:16:57Z","timestamp":1693736217902},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2014,9,3]],"date-time":"2014-09-03T00:00:00Z","timestamp":1409702400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2015,8]]},"DOI":"10.1007\/s10207-014-0260-y","type":"journal-article","created":{"date-parts":[[2014,9,2]],"date-time":"2014-09-02T10:00:28Z","timestamp":1409652028000},"page":"347-366","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Understanding the implemented access control policy of Android system services with slicing and extended static checking"],"prefix":"10.1007","volume":"14","author":[{"given":"Tanveer","family":"Mustafa","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Karsten","family":"Sohr","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,9,3]]},"reference":[{"key":"260_CR1","doi-asserted-by":"crossref","unstructured":"Anderson, P., Zarins, M.: The CodeSurfer software understanding platform. In: Proceedings of the 13th International Workshop on Program Comprehension, pp. 147\u2013148 (2005)","DOI":"10.1109\/WPC.2005.37"},{"key":"260_CR2","doi-asserted-by":"crossref","unstructured":"Au, K.W.Y., Zhou, Y.F., Huang, Z., Lie, D.: PScout: analyzing the android permission specification. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 217\u2013228. CCS \u201912, ACM, New York, NY, USA (2012)","DOI":"10.1145\/2382196.2382222"},{"key":"260_CR3","doi-asserted-by":"crossref","unstructured":"Bartel, A., Klein, J., Le Traon, Y., Monperrus, M.: Automatically securing permission-based software by reducing the attack surface: an application to android. In: Proceedings of the 27th IEEE\/ACM International Conference on Automated Software Engineering, pp. 274\u2013277. ASE 2012, ACM, New York, NY, USA (2012). doi: 10.1145\/2351676.2351722","DOI":"10.1145\/2351676.2351722"},{"key":"260_CR4","doi-asserted-by":"crossref","unstructured":"Bugiel, S., Davi, L., Dmitrienko, A., Heuser, S., Sadeghi, A.R., Shastry, B.: Practical and lightweight domain isolation on android. In: Proceedings of the 1st ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, pp. 51\u201362. SPSM \u201911, ACM (2011)","DOI":"10.1145\/2046614.2046624"},{"issue":"3","key":"260_CR5","doi-asserted-by":"crossref","first-page":"212","DOI":"10.1007\/s10009-004-0167-4","volume":"7","author":"L Burdy","year":"2005","unstructured":"Burdy, L., Cheon, Y., Cok, D.R., Ernst, M.D., Kiniry, J.R., Leavens, G.T., Leino, K.R.M., Poll, E.: An overview of JML tools and applications. Int. J. Softw. Tools Technol. Transf. 7(3), 212\u2013232 (2005)","journal-title":"Int. J. Softw. Tools Technol. Transf."},{"key":"260_CR6","doi-asserted-by":"crossref","unstructured":"Cata\u00f1o, N., Huisman, M.: Formal specification of Gemplus\u2019s electronic purse case study. In: FME 2002. vol. LNCS 2391, pp. 272\u2013289. Springer, Berlin (2002)","DOI":"10.1007\/3-540-45614-7_16"},{"key":"260_CR7","doi-asserted-by":"crossref","unstructured":"Chaudhuri, A.: Language-based security on android. In: Proceedings of the 4th ACM SIGPLAN Workshop on Programming Languages and Analysis for Security (PLAS\u201909), pp. 1\u20137. ACM (2009)","DOI":"10.1145\/1554339.1554341"},{"key":"260_CR8","unstructured":"Chen, H., Wagner, D., Dean, D.: Setuid demystified. In: Proceedings of the 11th USENIX Security Symposium, pp. 171\u2013190 (2002)"},{"key":"260_CR9","volume-title":"Secure Programming with Static Analysis","author":"B Chess","year":"2007","unstructured":"Chess, B., West, J.: Secure Programming with Static Analysis. Addison-Wesley, Reading, MA (2007)"},{"key":"260_CR10","doi-asserted-by":"crossref","unstructured":"Chess, B.: Improving computer security using extended static checking. In: IEEE Symposium on Security and Privacy, pp. 160\u2013173. IEEE Computer Society (2002)","DOI":"10.1109\/SECPRI.2002.1004369"},{"key":"260_CR11","doi-asserted-by":"crossref","unstructured":"Chin, E., Porter Felt, A., Greenwood, K., Wagner, D.: Analyzing inter-application communication in Android. In: Proceedings of the 9th International Conference on Mobile Systems, Applications, and Services (MobiSys 2011), Bethesda, USA, pp. 239\u2013252. ACM (2011)","DOI":"10.1145\/1999995.2000018"},{"key":"260_CR12","unstructured":"Dietz, M., Shekhar, S., Pisetsky, Y., Shu, A., Wallach, D.S.: Quire: lightweight provenance for smart phone operating systems. In: Proceedings of the 14th USENIX Security Symposium (2011)"},{"key":"260_CR13","unstructured":"Dolby, J., Sridharan, M.: Static and Dynamic Program Analysis Using WALA, PLDI Tutorial (2010). http:\/\/wala.sourceforge.net\/files\/PLDI_WALA_Tutorial.pdf"},{"key":"260_CR14","unstructured":"Enck, W., Octeau, D., McDaniel, P., Chaudhuri, S.: A study of android application security. In: Proceedings of the 14th USENIX Security Symposium (2011)"},{"key":"260_CR15","unstructured":"Enck, W., Gilbert, P., Chun, B.G, Cox, L.P., Jung, J., McDaniel, P., Sheth, A.N.: TaintDroid: an information-flow tracking system for realtime privacy monitoring on smartphones. In: 9th USENIX Symposium on Operating Systems Design and Implementation (2010)"},{"key":"260_CR16","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1109\/MSP.2009.26","volume":"7","author":"W Enck","year":"2009","unstructured":"Enck, W., Ongtang, M., McDaniel, P.: Understanding android security. IEEE Secur. Priv. 7, 50\u201357 (2009)","journal-title":"IEEE Secur. Priv."},{"key":"260_CR17","doi-asserted-by":"crossref","unstructured":"Enck, W., Ongtang, M., McDaniel, P.D.: On lightweight mobile phone application certification. In: Proceedings of the 2009 ACM Conference on Computer and Communications Security, CCS 2009, Chicago, Illinois, USA, November 9\u201313, 2009, pp. 235\u2013245. ACM (2009)","DOI":"10.1145\/1653662.1653691"},{"key":"260_CR18","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1016\/j.scico.2007.01.015","volume":"69","author":"MD Ernst","year":"2007","unstructured":"Ernst, M.D., Perkins, J.H., Guo, P.J., McCamant, S., Pacheco, C., Tschantz, M.S., Xiao, C.: The Daikon system for dynamic detection of likely invariants. Sci. Comput. Program. 69, 35\u201345 (2007)","journal-title":"Sci. Comput. Program."},{"key":"260_CR19","unstructured":"Felmetsger, V., Cavedon, L., Kruegel, C., Vigna, G.: Toward automated detection of logic vulnerabilities in web applications. In: USENIX Security Symposium, pp. 143\u2013160 (2010)"},{"key":"260_CR20","doi-asserted-by":"crossref","unstructured":"Flanagan, C., Leino, K.R.M., Lillibridge, M., Nelson, G., Saxe, J.B., Stata, R.: Extended static checking for Java. In: Proceedings of the ACM SIGPLAN Conference on Programming language Design and Implementation, pp. 234\u2013245. PLDI \u201902 (2002)","DOI":"10.1145\/512529.512558"},{"key":"260_CR21","unstructured":"Fortify Software: Fortify Source Code Analyser (2012) http:\/\/www.fortify.com\/products"},{"key":"260_CR22","doi-asserted-by":"crossref","unstructured":"Fragkaki, E., Bauer, L., Jia, L., Swasey, D.: Modeling and enhancing Android\u2019s permission system. In: 17th European Symposium on Research in Computer Security. LNCS, vol. 7459, pp. 1\u201318 (2012)","DOI":"10.1007\/978-3-642-33167-1_1"},{"key":"260_CR23","doi-asserted-by":"crossref","unstructured":"Gibler, C., Crussell, J., Erickson, J., Chen, H.: AndroidLeaks: automatically detecting potential privacy leaks in android applications on a large scale. In: Trust and Trustworthy Computing, LNCS, vol. 7344, pp. 291\u2013307. Springer, Berlin (2012)","DOI":"10.1007\/978-3-642-30921-2_17"},{"key":"260_CR24","unstructured":"Google Inc.: Bluetooth (2012). http:\/\/developer.android.com\/guide\/topics\/wireless\/bluetooth.html"},{"key":"260_CR25","unstructured":"Google Inc.: Permissions (2012). http:\/\/developer.android.com\/guide\/topics\/security\/permissions.html"},{"key":"260_CR26","unstructured":"Grace, M., Zhou, Y., Wang, Z., Jiang, X.: Systematic detection of capability leaks in stock android smartphones. In: Proceedings of the 19th Network and Distributed System Security Symposium (NDSS 2012). USENIX Association (2012)"},{"key":"260_CR27","doi-asserted-by":"crossref","unstructured":"Hatcliff, J., Leavens, G.T., Leino, K.R.M., M\u00fcller, P., Parkinson, M.: Behavioral interface specification languages. ACM Comput. Surv. 44(3), 16:1\u201316:58 (2012)","DOI":"10.1145\/2187671.2187678"},{"issue":"1","key":"260_CR28","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1145\/77606.77608","volume":"12","author":"S Horwitz","year":"1990","unstructured":"Horwitz, S., Reps, T., Binkley, D.: Interprocedural slicing using dependence graphs. ACM Trans. Program. Lang. Syst. 12(1), 26\u201360 (1990)","journal-title":"ACM Trans. Program. Lang. Syst."},{"issue":"2","key":"260_CR29","doi-asserted-by":"crossref","first-page":"175","DOI":"10.1145\/996943.996944","volume":"7","author":"T Jaeger","year":"2004","unstructured":"Jaeger, T., Edwards, A., Zhang, X.: Consistency analysis of authorization hook placement in the Linux security modules framework. ACM Trans. Inf. Syst. Secur. 7(2), 175\u2013205 (2004)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"260_CR30","unstructured":"Krinke, J.: Advanced Slicing of Sequential and Concurrent Programs. Ph.D. Thesis, Universit\u00e4t Passau (2003)"},{"key":"260_CR31","doi-asserted-by":"crossref","unstructured":"Leavens, G.T., Baker, A.L., Ruby, C.: JML: A notation for detailed design. In: Behavioral Specifications of Businesses and Systems, pp. 175\u2013188. Kluwer, Dordrecht (1999)","DOI":"10.1007\/978-1-4615-5229-1_12"},{"key":"260_CR32","doi-asserted-by":"crossref","unstructured":"Leino, K.R.M.: Applications of extended static checking. In: Proceedings of the 8th International Symposium on Static Analysis SAS. LNCS, vol. 2126, pp. 185\u2013193. Springer, Berlin (2001)","DOI":"10.1007\/3-540-47764-0_11"},{"key":"260_CR33","doi-asserted-by":"crossref","unstructured":"Lloyd, J., J\u00fcrjens, J.: Security analysis of a biometric authentication system using UMLsec and JML. In: MoDELS. Lecture Notes in Computer Science, vol. 5795, pp. 77\u201391. Springer, Berlin (2009)","DOI":"10.1007\/978-3-642-04425-0_7"},{"key":"260_CR34","doi-asserted-by":"crossref","unstructured":"Lu, L., Li, Z., Wu, Z., Lee, W., Jiang, G.: CHEX: statically vetting Android apps for component hijacking vulnerabilities. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 229\u2013240. CCS \u201912 (2012)","DOI":"10.1145\/2382196.2382223"},{"issue":"1","key":"260_CR35","first-page":"19","volume":"10","author":"B Meyer","year":"1989","unstructured":"Meyer, B.: From structured programming to object-oriented design: the road to Eiffel. Struct. Program. 10(1), 19\u201339 (1989)","journal-title":"Struct. Program."},{"key":"260_CR36","doi-asserted-by":"crossref","unstructured":"Ongtang, M., McLaughlin, S., Enck, W., McDaniel, P.: Semantically rich application-centric security in Android. In: Proceedings of the 25th Annual Computer Security Applications Conference, pp. 340\u2013349 (2009)","DOI":"10.1109\/ACSAC.2009.39"},{"key":"260_CR37","unstructured":"Oracle Inc.: Compiler Tree API (2012). http:\/\/docs.oracle.com\/javase\/6\/docs\/jdk\/api\/javac\/tree\/com\/sun\/source\/util\/package-summary.html"},{"key":"260_CR38","unstructured":"Pivotal Inc: Spring security 3.1.2 (2013). http:\/\/static.springsource.org\/spring-security\/site\/index.html"},{"key":"260_CR39","doi-asserted-by":"crossref","unstructured":"Felt, A.P., Chin, E., Hanna, S., Song, D., Wagner, D.: Android permissions demystified. In: Proceedings of the 18th ACM Conference on Computer and Communications Security, Chicago, USA, pp. 627\u2013638. ACM (2011)","DOI":"10.1145\/2046707.2046779"},{"key":"260_CR40","unstructured":"Felt, A.P., Chin, E., Hanna, S., Song, D., Wagner, D.: STOWAWAY (2011). http:\/\/www.android-permissions.org\/permissionmap.html"},{"key":"260_CR41","unstructured":"Spark, D.: Enable camera permission check (2009), bug ID = 1869264"},{"key":"260_CR42","doi-asserted-by":"crossref","unstructured":"Sridharan, M., Fink, S.J., Bodik, R.: Thin slicing. In: Proceedings of the 2007 ACM SIGPLAN Conference on Programming Language Design and Implementation, pp. 112\u2013122. PLDI \u201907 (2007)","DOI":"10.1145\/1250734.1250748"},{"key":"260_CR43","unstructured":"Warnier, M.: Language Based Security for Java and JML. Ph.D. Thesis, Radboud University, Nijmegen, Netherlands (2006)"},{"key":"260_CR44","unstructured":"Weiser, M.: Program slicing. In: Proceedings of the International Conference on Software Engineering, pp. 439\u2013449. IEEE Press, Piscataway, NJ, USA (1981)"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0260-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-014-0260-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0260-y","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,14]],"date-time":"2019-08-14T11:39:56Z","timestamp":1565782796000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-014-0260-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,9,3]]},"references-count":44,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2015,8]]}},"alternative-id":["260"],"URL":"https:\/\/doi.org\/10.1007\/s10207-014-0260-y","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,9,3]]}}}