{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T23:05:00Z","timestamp":1778713500987,"version":"3.51.4"},"reference-count":108,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2019,2,20]],"date-time":"2019-02-20T00:00:00Z","timestamp":1550620800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2019,8]]},"DOI":"10.1007\/s10664-019-09689-7","type":"journal-article","created":{"date-parts":[[2019,2,20]],"date-time":"2019-02-20T03:47:34Z","timestamp":1550634454000},"page":"2056-2101","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["The Android OS stack and its vulnerabilities: an empirical study"],"prefix":"10.1007","volume":"24","author":[{"given":"Alejandro","family":"Mazuera-Rozo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jairo","family":"Bautista-Mora","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0161-2888","authenticated-orcid":false,"given":"Mario","family":"Linares-V\u00e1squez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sandra","family":"Rueda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gabriele","family":"Bavota","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,2,20]]},"reference":[{"key":"9689_CR1","unstructured":"Aosp commit cf1581c66c2ad8c5b1aaca2e43e350cf5974f46d (2017a) http:\/\/tinyurl.com\/hxqdp7f"},{"key":"9689_CR2","unstructured":"Aosp commit 8ec845c8fe0f03bc57c901bc484541bdd6a7cf80 (2017b) http:\/\/tinyurl.com\/hvndh7r"},{"key":"9689_CR3","unstructured":"Aosp commit edd4a76eb4747bd19ed122df46fa46b452c12a0d (2017c) http:\/\/tinyurl.com\/hkw399d"},{"key":"9689_CR4","doi-asserted-by":"publisher","unstructured":"Ahmad W, K\u00e4stner C, Sunshine J, Aldrich J (2016) Inter-app communication in android: Developer challenges. In: Proceedings of the 13th international conference on mining software repositories, MSR \u201916. ACM, New York, pp 177\u2013188. https:\/\/doi.org\/10.1145\/2901739.2901762","DOI":"10.1145\/2901739.2901762"},{"key":"9689_CR5","unstructured":"Anderson B, et al. (2016) Hpe security research. cyber risk report 2016. Tech. rep., Hewlett Packard"},{"key":"9689_CR6","unstructured":"Armis (2017) The attack vector \u201cblueborne\u201d exposes almost every connected device. https:\/\/www.armis.com\/blueborne\/"},{"key":"9689_CR7","doi-asserted-by":"publisher","unstructured":"Arzt S, Rasthofer S, Fritz C, Bodden E, Bartel A, Klein J, Le Traon Y, Octeau D, McDaniel P (2014) Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. In: Proceedings of the 35th ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI \u201914. ACM, New York, pp 259\u2013269. https:\/\/doi.org\/10.1145\/2594291.2594299","DOI":"10.1145\/2594291.2594299"},{"key":"9689_CR8","doi-asserted-by":"crossref","unstructured":"Avdiienko V, Kuznetsov K, Gorla A, Zeller A, Arzt S, Rasthofer S, Bodden E (2015) Mining apps for abnormal usage of sensitive data. In: ICSE\u201915, pp 426\u2013436. http:\/\/dl.acm.org\/citation.cfm?id=2818754.2818808","DOI":"10.1109\/ICSE.2015.61"},{"key":"9689_CR9","doi-asserted-by":"publisher","unstructured":"Backes M, Bugiel S, Derr E (2016) Reliable third-party library detection in android and its security applications. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, CCS \u201916. ACM, New York, pp 356\u2013367. https:\/\/doi.org\/10.1145\/2976749.2978333","DOI":"10.1145\/2976749.2978333"},{"key":"9689_CR10","unstructured":"Bagheri H, Kang E, Malek S, Jackson D (In Press) A formal approach for detection of security flaws in the android permission system. Springer Journal on Formal Aspects of Computing"},{"issue":"9","key":"9689_CR11","doi-asserted-by":"publisher","first-page":"866","DOI":"10.1109\/TSE.2015.2419611","volume":"41","author":"H Bagheri","year":"2015","unstructured":"Bagheri H, Sadeghi A, Garcia J, Malek S (2015) Covert: compositional analysis of android inter-app permission leakage. IEEE Trans Softw Eng 41(9):866\u2013886. https:\/\/doi.org\/10.1109\/TSE.2015.2419611","journal-title":"IEEE Trans Softw Eng"},{"key":"9689_CR12","unstructured":"Beres D (2015) \u2018cowboy adventure\u2019 game infects up to 1 million android users with malware. http:\/\/www.huffingtonpost.com\/2015\/07\/10\/android-security_n_7765842.html"},{"key":"9689_CR13","unstructured":"Bhosale A (2014) Precise static analysis of taint flow for android application sets. Master\u2019s thesis, Heinz College Carnegie Mellon University"},{"key":"9689_CR14","unstructured":"Brady P (2008) Anatomy & physiology of an android. https:\/\/sites.google.com\/site\/io\/anatomy--physiology-of-an-android https:\/\/sites.google.com\/site\/io\/anatomy--physiology-of-an-android"},{"key":"9689_CR15","unstructured":"Burgess M (2016) Millions of android devices vulnerable to new stagefright exploit. http:\/\/www.wired.co.uk\/article\/stagefright-android-real-world-hack"},{"key":"9689_CR16","doi-asserted-by":"publisher","unstructured":"Cao C, Gao N, Liu P, Xiang J (2015) Towards analyzing the input validation vulnerabilities associated with android system services. In: Proceedings of the 31st annual computer security applications conference, ACSAC 2015. ACM, New York, pp 361\u2013370. https:\/\/doi.org\/10.1145\/2818000.2818033","DOI":"10.1145\/2818000.2818033"},{"key":"9689_CR17","unstructured":"Castellanos JH, Wuchner T, Ochoa M, Rueda S (2016) Q-floid: Android malware detection with quantitative data flow graphs. In: Singapore cyber-security conference (SG-CRC). IOS Press, pp 13\u201326"},{"key":"9689_CR18","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-9816-3","volume-title":"Plane Answers to Complex Questions: The Theory of Linear models","author":"R Christensen","year":"2011","unstructured":"Christensen R (2011) Plane Answers to Complex Questions: The Theory of Linear models, 4th edn. Springer Texts in Statistics Springer, Berlin","edition":"4th edn."},{"key":"9689_CR19","volume-title":"Practical Nonparametric Statistics","author":"WJ Conover","year":"1998","unstructured":"Conover WJ (1998) Practical Nonparametric Statistics, 3rd edn. Wiley, New York","edition":"3rd edn."},{"key":"9689_CR20","unstructured":"Corporation M (2017) Cve common vulnerabilities and exposures. http:\/\/cve.mitre.org"},{"key":"9689_CR21","volume-title":"Introduction to the new Statistics: Effect sizes, confidence intervals, and Meta-Analysis","author":"G Cumming","year":"2011","unstructured":"Cumming G (2011) Introduction to the new Statistics: Effect sizes, confidence intervals, and Meta-Analysis. Routledge, Evanston"},{"key":"9689_CR22","unstructured":"Cve-2012-6636 (2017) https:\/\/www.cvedetails.com\/cve\/cve-2012-6636"},{"key":"9689_CR23","doi-asserted-by":"crossref","unstructured":"Dimja\u0161evic M, Atzeni S, Ugrina I, Rakamaric Z (2015) Android malware detection based on system calls","DOI":"10.1145\/2875475.2875487"},{"key":"9689_CR24","volume-title":"Android hacker\u2019s handbook","author":"JJ Drake","year":"2014","unstructured":"Drake JJ, Lanier Z, Mulliner C, Fora PO, Ridley SA, Wicherski G (2014) Android hacker\u2019s handbook. Wiley, New York"},{"key":"9689_CR25","unstructured":"Enck W, Gilbert P, Chun BG, Cox L, Jung J, McDaniel P, Sheth AN (2010) Taintdroid: an information-flow tracking system for realtime privacy monitoring on smartphones. In: Proceedings of the 9th USENIX conference on operating systems design and implementation, OSDI\u201910. USENIX Association, Berkeley, pp 393\u2013407. http:\/\/dl.acm.org\/citation.cfm?id=1924943.1924971"},{"key":"9689_CR26","doi-asserted-by":"publisher","unstructured":"Enck W, Ongtang M, McDaniel P (2009) On lightweight mobile phone application certification. In: Proceedings of the 16th ACM conference on computer and communications security, CCS \u201909. ACM, New York, pp 235\u2013245. https:\/\/doi.org\/10.1145\/1653662.1653691","DOI":"10.1145\/1653662.1653691"},{"key":"9689_CR27","doi-asserted-by":"publisher","unstructured":"Fahl S, Harbach M, Muders T, Baumg\u00e4rtner L., Freisleben B, Smith M (2012) Why eve and mallory love android: an analysis of android ssl (in)security. In: Proceedings of the 2012 ACM conference on computer and communications security, CCS \u201912. ACM, New York, pp 50\u201361. https:\/\/doi.org\/10.1145\/2382196.2382205","DOI":"10.1145\/2382196.2382205"},{"key":"9689_CR28","unstructured":"Fattori A, Tam K, Khan SJ, Cavallaro L, Reina A (2014) CopperDroid: On the Reconstruction of Android Malware Behaviors. Tech. rep. Royal Holloway University of London"},{"key":"9689_CR29","unstructured":"FIRST Organization (2019) Common vulnerability scoring system sig. https:\/\/www.first.org\/cvss"},{"key":"9689_CR30","unstructured":"for Standardization IO (2011) Iso 27005 information security risk management"},{"key":"9689_CR31","doi-asserted-by":"publisher","unstructured":"Garcia J, Hammad M, Ghorbani N, Malek S (2017) Automatic generation of inter-component communication exploits for android applications. In: Proceedings of the 2017 11th joint meeting on foundations of software engineering, ESEC\/FSE 2017. ACM, New York, pp 661\u2013671. https:\/\/doi.org\/10.1145\/3106237.3106286","DOI":"10.1145\/3106237.3106286"},{"key":"9689_CR32","doi-asserted-by":"publisher","unstructured":"Gasior W, Yang L (2012) Exploring covert channel in android platform. In: 2012 international conference on cyber security, pp 173\u2013177. https:\/\/doi.org\/10.1109\/CyberSecurity.2012.29","DOI":"10.1109\/CyberSecurity.2012.29"},{"key":"9689_CR33","doi-asserted-by":"publisher","unstructured":"Ghafari M, Gadient P, Nierstrasz O (2017) Security smells in android. In: 2017 IEEE 17th international working conference on source code analysis and manipulation (SCAM), pp 121\u2013130. https:\/\/doi.org\/10.1109\/SCAM.2017.24","DOI":"10.1109\/SCAM.2017.24"},{"key":"9689_CR34","doi-asserted-by":"publisher","unstructured":"Gilbert P, Chun BG, Cox LP, Jung J (2011) Vision: automated security validation of mobile apps at app markets. In: Proceedings of the second international workshop on mobile cloud computing and services, MCS \u201911. ACM, New York, pp 21\u201326. https:\/\/doi.org\/10.1145\/1999732.1999740","DOI":"10.1145\/1999732.1999740"},{"key":"9689_CR35","doi-asserted-by":"publisher","unstructured":"Gorla A, Tavecchia I, Gross F, Zeller A (2014) Checking app behavior against app descriptions. In: ICSE\u201914, pp 1025\u20131035. https:\/\/doi.org\/10.1145\/2568225.2568276","DOI":"10.1145\/2568225.2568276"},{"key":"9689_CR36","doi-asserted-by":"crossref","unstructured":"Google (2016) Android security 2015 year in review. https:\/\/static.googleusercontent.com\/media\/source.android.com\/en\/\/security\/reports\/Google_Android_Security_2015_Report_Final.pdf","DOI":"10.1016\/S1353-4858(15)30046-5"},{"key":"9689_CR37","unstructured":"Google (2017a) Android security bulletins. https:\/\/source.android.com\/security\/bulletin\/"},{"key":"9689_CR38","unstructured":"Google (2017b) Platform architecture. https:\/\/developer.android.com\/guide\/platform\/index.html"},{"key":"9689_CR39","unstructured":"Graf J, Hecker MMM (2015) Jodroid: Adding android support to a static information flow control tool. In: Working conference on programming languages"},{"key":"9689_CR40","volume-title":"Effect sizes for research: a broad practical approach","author":"RJ Grissom","year":"2005","unstructured":"Grissom RJ, Kim JJ (2005) Effect sizes for research: a broad practical approach, 2nd edn. Lawrence Earlbaum Associates, New Jersey","edition":"2nd edn."},{"key":"9689_CR41","volume-title":"Statistical methods for Meta-Analysis","author":"LV Hedges","year":"1985","unstructured":"Hedges LV, Olkin I (1985) Statistical methods for Meta-Analysis. Academic Press, New York"},{"key":"9689_CR42","doi-asserted-by":"crossref","unstructured":"Herzig K, Zeller A (2013) The impact of tangled code changes. In: Proceedings of the 10th Working Conference on Mining Software Repositories, MSR \u201913, San Francisco, pp 121\u2013130","DOI":"10.1109\/MSR.2013.6624018"},{"key":"9689_CR43","first-page":"65","volume":"6","author":"S Holm","year":"1979","unstructured":"Holm S (1979) A simple sequentially rejective Bonferroni test procedure. Scand J Stat 6:65\u201370","journal-title":"Scand J Stat"},{"key":"9689_CR44","doi-asserted-by":"publisher","unstructured":"Huang H, Zhu S, Chen K, Liu P (2015) From system services freezing to system server shutdown in android: All you need is a loop in an app. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, CCS \u201915. ACM, New York, pp 1236\u20131247. https:\/\/doi.org\/10.1145\/2810103.2813606","DOI":"10.1145\/2810103.2813606"},{"key":"9689_CR45","doi-asserted-by":"publisher","unstructured":"Jimenez M, Papadakis M, Bissyand\u00e9 TF, Klein J (2016) Profiling android vulnerabilities. In: 2016 IEEE International conference on software quality, reliability and security (QRS), pp 222\u2013229. https:\/\/doi.org\/10.1109\/QRS.2016.34 https:\/\/doi.org\/10.1109\/QRS.2016.34","DOI":"10.1109\/QRS.2016.34 10.1109\/QRS.2016.34"},{"key":"9689_CR46","doi-asserted-by":"publisher","unstructured":"Kantola D, Chin E, He W, Wagner D (2012) Reducing attack surfaces for intra-application communication in android. In: Proceedings of the second ACM workshop on security and privacy in smartphones and mobile devices, SPSM \u201912. ACM, New York, pp 69\u201380. https:\/\/doi.org\/10.1145\/2381934.2381948","DOI":"10.1145\/2381934.2381948"},{"key":"9689_CR47","doi-asserted-by":"crossref","unstructured":"Kim S, James Whitehead Jr E, Zhang Y (2008) Classifying software changes: clean or buggy? IEEE Trans Softw Eng 34(2):181\u2013196","DOI":"10.1109\/TSE.2007.70773"},{"key":"9689_CR48","doi-asserted-by":"publisher","unstructured":"Lal S, Sureka A (2012) Comparison of seven bug report types: a case-study of google chrome browser project. In: 2012 19th asia-pacific software engineering conference, vol 1, pp 517\u2013526. https:\/\/doi.org\/10.1109\/APSEC.2012.54","DOI":"10.1109\/APSEC.2012.54"},{"key":"9689_CR49","doi-asserted-by":"crossref","unstructured":"Lee S, Hwang S, Ryu S (2017) All about activity injection: Threats, semantics, and detection. In: Proceedings of the 32nd IEEE\/ACM international conference on automated software engineering, ASE 2017. IEEE Press, Piscataway, pp 252\u2013262. http:\/\/dl.acm.org\/citation.cfm?id=3155562.3155597","DOI":"10.1109\/ASE.2017.8115638"},{"issue":"1","key":"9689_CR50","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1348\/000711006X126600","volume":"61","author":"GK Li","year":"2010","unstructured":"Li GK (2010) Computing inter-rater reliability and its variance in the presence of high agreement. Br J Math Stat Psychol 61(1):29\u201348. https:\/\/doi.org\/10.1348\/000711006X126600","journal-title":"Br J Math Stat Psychol"},{"key":"9689_CR51","doi-asserted-by":"publisher","unstructured":"Linares-V\u00e1squez M, Bavota G, Escobar-Vel\u00e1squez C (2017) An empirical study on android-related vulnerabilities. In: Proceedings of the 14th international conference on mining software repositories, MSR \u201917. IEEE Press, Piscataway, pp 2\u201313. https:\/\/doi.org\/10.1109\/MSR.2017.60","DOI":"10.1109\/MSR.2017.60"},{"key":"9689_CR52","unstructured":"LLC PI (2014) The security impact of mobile device use by employees. Tech. rep., Ponemon Institute"},{"key":"9689_CR53","doi-asserted-by":"crossref","unstructured":"Lu L, Li Z, Wu Z, Lee W, Jiang G (2012) Chex: statically vetting android apps for component hijacking vulnerabilities. In: ACM Conference on computer and communications security, pp 229\u2013240","DOI":"10.1145\/2382196.2382223"},{"key":"9689_CR54","unstructured":"Mazuera-Rozo A, Bautista-Mora J, Linares-V\u00e1squez M, Rueda S, Bavota G (2017) Replication package: \u201cThe Android OS Stack and its Vulnerabilities: An Empirical Study\u201d. http:\/\/ml-papers.gitlab.io\/android.vulnerabilities-2017\/appendix\/"},{"key":"9689_CR55","unstructured":"Mell P, Scarfone K, Romanosky S (2007) A Complete Guide to the Common Vulnerability Scoring System Version 2.0, 2.0 edn"},{"key":"9689_CR56","unstructured":"MITRE (2017a) Cwe-120: Buffer copy without checking size of input (\u2018classic buffer overflow\u2019). https:\/\/cwe.mitre.org\/data\/definitions\/120.html"},{"key":"9689_CR57","unstructured":"MITRE (2017b) Cwe-121: Stack-based buffer overflow. https:\/\/cwe.mitre.org\/data\/definitions\/121.html"},{"key":"9689_CR58","unstructured":"MITRE (2017c) Cwe-122: Heap-based buffer overflow. https:\/\/cwe.mitre.org\/data\/definitions\/122.html"},{"key":"9689_CR59","unstructured":"MITRE (2017d) Cwe-190: Integer overflow or wraparound. https:\/\/cwe.mitre.org\/data\/definitions\/190.html"},{"key":"9689_CR60","unstructured":"MITRE (2017e) Cwe-201: Information exposure through sent data. https:\/\/cwe.mitre.org\/data\/definitions\/201.html"},{"key":"9689_CR61","unstructured":"MITRE (2017f) Cwe-275: Permission issues. https:\/\/cwe.mitre.org\/data\/definitions\/275.html"},{"key":"9689_CR62","unstructured":"MITRE (2017g) Cwe-296: Improper following of a certificate\u2019s chain of trust. https:\/\/cwe.mitre.org\/data\/definitions\/296.html"},{"key":"9689_CR63","unstructured":"MITRE (2017h) Cwe-326: Inadequate encryption strength. https:\/\/cwe.mitre.org\/data\/definitions\/326.html"},{"key":"9689_CR64","unstructured":"MITRE (2017i) Cwe-327: Use of a broken or risky cryptographic algorithm. https:\/\/cwe.mitre.org\/data\/definitions\/327.html"},{"key":"9689_CR65","unstructured":"MITRE (2017j) Cwe-415: Double free. https:\/\/cwe.mitre.org\/data\/definitions\/415.html"},{"key":"9689_CR66","unstructured":"MITRE (2017k) Cwe-787: Out-of-bounds write. https:\/\/cwe.mitre.org\/data\/definitions\/787.html"},{"key":"9689_CR67","unstructured":"MITRE (2017l) Cwe-840: Business logic errors. https:\/\/cwe.mitre.org\/data\/definitions\/840.html"},{"key":"9689_CR68","unstructured":"MITRE (2017m) Cwe-862: Missing authorization. https:\/\/cwe.mitre.org\/data\/definitions\/862.html"},{"key":"9689_CR69","unstructured":"MITRE (2017n) Cwe-909: Missing initialization of resource. https:\/\/cwe.mitre.org\/data\/definitions\/909.html"},{"key":"9689_CR70","unstructured":"MITRE (2017o) Cwe-94: Improper control of generation of code (\u2019code injection\u2019). https:\/\/cwe.mitre.org\/data\/definitions\/94.html"},{"key":"9689_CR71","unstructured":"MITRE (2017p) Common weakness enumeration http:\/\/cwe.mitre.org\/"},{"key":"9689_CR72","unstructured":"MITRE (2017q) Cve details Android vulnerabilities. https:\/\/www.cvedetails.com\/product\/19997\/Google-Android.html"},{"key":"9689_CR73","unstructured":"MITRE (2017r) Cve details. https:\/\/www.cvedetails.com\/"},{"issue":"4","key":"9689_CR74","doi-asserted-by":"publisher","first-page":"1160","DOI":"10.1109\/TLA.2015.7106371","volume":"13","author":"LV Morales","year":"2015","unstructured":"Morales LV, Rueda SJ (2015) Meaningful permission management in android. IEEE Lat Am Trans 13(4):1160\u20131166. https:\/\/doi.org\/10.1109\/TLA.2015.7106371","journal-title":"IEEE Lat Am Trans"},{"key":"9689_CR75","unstructured":"Nickinson P (2015) The \u2019stagefright\u2019 exploit: what you need to know. http:\/\/www.androidcentral.com\/stagefright"},{"key":"9689_CR76","unstructured":"NIST (2015) Common vulnerability scoring system calculator version 2. https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\/v2-calculator"},{"key":"9689_CR77","unstructured":"NIST (2017) Nvd data feeds http:\/\/nvd.nist.gov\/download.cfm#{RSS}"},{"key":"9689_CR78","doi-asserted-by":"publisher","unstructured":"Novak E, Tang Y, Hao Z, Li Q, Zhang Y (2015) Physical media covert channels on smart mobile devices. In: Proceedings of the 2015 ACM international joint conference on pervasive and ubiquitous computing, UbiComp \u201915. ACM, New York, pp 367\u2013378. https:\/\/doi.org\/10.1145\/2750858.2804253","DOI":"10.1145\/2750858.2804253"},{"issue":"PART B","key":"9689_CR79","doi-asserted-by":"publisher","first-page":"419","DOI":"10.1016\/j.cose.2013.09.006","volume":"39","author":"Y Park","year":"2013","unstructured":"Park Y, Reeves DS (2013) Deriving common malware behavior through graph clustering. Comput Secur 39(PART B):419\u2013430. https:\/\/doi.org\/10.1016\/j.cose.2013.09.006","journal-title":"Comput Secur"},{"key":"9689_CR80","unstructured":"Ren C, Zhang Y, Xue H, Wei T, Liu P (2015) Towards discovering and understanding task hijacking in android. In: Proceedings of the 24th USENIX conference on security symposium, SEC\u201915. USENIX Association, Berkeley, pp 945\u2013959. http:\/\/dl.acm.org\/citation.cfm?id=2831143.2831203"},{"key":"9689_CR81","unstructured":"Rust (2013) https:\/\/www.rust-lang.org"},{"key":"9689_CR82","doi-asserted-by":"crossref","unstructured":"Sadeghi A, Bagheri H, Malek S (2015) Analysis of android inter-app security vulnerabilities using covert. In: ICSE\u201915, pp 725\u2013728. http:\/\/dl.acm.org\/citation.cfm?id=2819009.2819149","DOI":"10.1109\/ICSE.2015.233"},{"issue":"99","key":"9689_CR83","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TSE.2016.2615307","volume":"PP","author":"A Sadeghi","year":"2016","unstructured":"Sadeghi A, Bagheri H, Garcia J, Malek S (2016) A taxonomy and qualitative comparison of program analysis techniques for security assessment of android software. IEEE Trans Softw Eng PP(99):1\u20131. https:\/\/doi.org\/10.1109\/TSE.2016.2615307","journal-title":"IEEE Trans Softw Eng"},{"key":"9689_CR84","doi-asserted-by":"publisher","unstructured":"Sadeghi A, Jabbarvand R, Malek S (2017) Patdroid: Permission-aware gui testing of android. In: Proceedings of the 2017 11th joint meeting on foundations of software engineering, ESEC\/FSE 2017. ACM, New York, pp 220\u2013232. https:\/\/doi.org\/10.1145\/3106237.3106250","DOI":"10.1145\/3106237.3106250"},{"issue":"6","key":"9689_CR85","doi-asserted-by":"publisher","first-page":"2:10","DOI":"10.1147\/JRD.2013.2284403","volume":"57","author":"D Sb\u00eerlea","year":"2013","unstructured":"Sb\u00eerlea D, Burke MG, Guarnieri S, Pistoia M, Sarkar V (2013) Automatic detection of inter-application permission leaks in android applications. IBM J Res Dev 57(6):2:10\u20132:10. https:\/\/doi.org\/10.1147\/JRD.2013.2284403 https:\/\/doi.org\/10.1147\/JRD.2013.2284403","journal-title":"IBM J Res Dev"},{"key":"9689_CR86","doi-asserted-by":"crossref","unstructured":"Sliwerski J, Zimmermann T, Zeller A (2005) When do changes induce fixes? In: Proceedings of the 2005 International Workshop on Mining Software Repositories","DOI":"10.1145\/1083142.1083147"},{"key":"9689_CR87","unstructured":"Stefanko L (2015) Aggressive android ransomware spreading in the usa. http:\/\/www.welivesecurity.com\/2015\/09\/10\/aggressive-android-ransomware-spreading-in-the-usa\/"},{"issue":"4","key":"9689_CR88","doi-asserted-by":"publisher","first-page":"58:1","DOI":"10.1145\/2733306","volume":"47","author":"DJJ Sufatrio Tan","year":"2015","unstructured":"Sufatrio Tan DJJ, Chua TW, Thing VLL (2015) Securing android: a survey, taxonomy, and challenges. ACM Comput Surv 47(4):58:1\u201358:45. https:\/\/doi.org\/10.1145\/2733306","journal-title":"ACM Comput Surv"},{"key":"9689_CR89","doi-asserted-by":"publisher","unstructured":"Thomas DR (2015a) The Lifetime of Android API Vulnerabilities: Case Study on the JavaScript-to-Java Interface (Transcript of Discussion). Springer International Publishing, Cham, pp 139\u2013144. https:\/\/doi.org\/10.1007\/978-3-319-26096-9_14","DOI":"10.1007\/978-3-319-26096-9_14"},{"key":"9689_CR90","doi-asserted-by":"publisher","unstructured":"Thomas DR, Beresford AR, Rice A (2015b) Security metrics for the android ecosystem. In: Proceedings of the 5th annual ACM CCS workshop on security and privacy in smartphones and mobile devices, SPSM \u201915. ACM, New York, pp 87\u201398. https:\/\/doi.org\/10.1145\/2808117.2808118","DOI":"10.1145\/2808117.2808118"},{"key":"9689_CR91","doi-asserted-by":"publisher","unstructured":"Tufano M, Watson C, Bavota G, Di Penta M, White M, Poshyvanyk D (2018) An empirical investigation into learning bug-fixing patches in the wild via neural machine translation. In: Proceedings of the 33rd ACM\/IEEE international conference on automated software engineering, ASE 2018. ACM, New York, pp 832\u2013837. https:\/\/doi.org\/10.1145\/3238147.3240732","DOI":"10.1145\/3238147.3240732"},{"key":"9689_CR92","unstructured":"U.S. National Institute of Standards and Technology - NIST (2012) National vulnerability database. http:\/\/nvd.nist.gov"},{"key":"9689_CR93","unstructured":"U.S. National Institute of Standards and Technology - NIST (2012) Sp 800-30 guide for conducting risk assessments"},{"key":"9689_CR94","unstructured":"VisionMobile: Developer economics q1 2014 (2014) State of the developer nation. Tech. rep."},{"key":"9689_CR95","doi-asserted-by":"publisher","unstructured":"Wang K, Zhang Y, Liu P (2016) Call me back!: Attacks on system server and system apps in android through synchronous callback. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, CCS \u201916. ACM, New York, pp 92\u2013103. https:\/\/doi.org\/10.1145\/2976749.2978342","DOI":"10.1145\/2976749.2978342"},{"key":"9689_CR96","unstructured":"Weichselbaum L, Neugschwandtner M, Lindorfer M, Fratantonio Y, Veen VVD, Platzer C (2012) ANDRUBIS: Android Malware Under The Magnifying Glass. Tech. rep., Vienna University of Technology. https:\/\/www.iseclab.org\/papers\/andrubis_techreport.pdf"},{"key":"9689_CR97","unstructured":"wiki. L (2015) Android kernel features. http:\/\/elinux.org\/Android_Kernel_Features"},{"key":"9689_CR98","unstructured":"Wikipedia (2017a) Android version history https:\/\/en.wikipedia.org\/wiki\/Android_version_history"},{"key":"9689_CR99","unstructured":"Wikipedia (2017b) Heartbleed https:\/\/en.wikipedia.org\/wiki\/Heartbleed"},{"key":"9689_CR100","unstructured":"Wikipedia (2017c) Stagefright https:\/\/en.wikipedia.org\/wiki\/Stagefright_(bug)"},{"key":"9689_CR101","doi-asserted-by":"publisher","unstructured":"Wu L, Grace M, Zhou Y, Wu C, Jiang X (2013) The impact of vendor customizations on android security. In: Proceedings of the 2013 ACM SIGSAC conference on computer & communications security, CCS \u201913. ACM, New York, pp 623\u2013634. https:\/\/doi.org\/10.1145\/2508859.2516728","DOI":"10.1145\/2508859.2516728"},{"key":"9689_CR102","doi-asserted-by":"crossref","unstructured":"Xiao X, Tillman N, Fahndrich M, DeHalleux J, Moskal M (2012) User-aware privacy control via extended static-information-flow analysis. In: IEEE\/ACM international conference on automated software engineering","DOI":"10.1145\/2351676.2351689"},{"issue":"2","key":"9689_CR103","doi-asserted-by":"publisher","first-page":"38:1","DOI":"10.1145\/2963145","volume":"49","author":"M Xu","year":"2016","unstructured":"Xu M, Song C, Ji Y, Shih MW, Lu K, Zheng C, Duan R, Jang Y, Lee B, Qian C, Lee S, Kim T (2016) Toward engineering a secure android ecosystem: a survey of existing techniques. ACM Comput Surv 49(2):38:1\u201338:47. https:\/\/doi.org\/10.1145\/2963145","journal-title":"ACM Comput Surv"},{"key":"9689_CR104","doi-asserted-by":"publisher","unstructured":"You W, Liang B, Shi W, Zhu S, Wang P, Xie S, Zhang X (2016) Reference hijacking: Patching, protecting and analyzing on unmodified and non-rooted android devices. In: Proceedings of the 38th international conference on software engineering, ICSE \u201916. ACM, New York, pp 959\u2013970. https:\/\/doi.org\/10.1145\/2884781.2884863","DOI":"10.1145\/2884781.2884863"},{"key":"9689_CR105","doi-asserted-by":"publisher","unstructured":"Zaman S, Adams B, Hassan AE (2011) Security versus performance bugs: a case study on firefox. In: Proceedings of the 8th working conference on mining software repositories, MSR\u201911. ACM, New York, pp 93\u2013102. https:\/\/doi.org\/10.1145\/1985441.1985457","DOI":"10.1145\/1985441.1985457"},{"key":"9689_CR106","doi-asserted-by":"crossref","unstructured":"Zhou Y, Jiang X (2012) Android malware genome project. http:\/\/www.malgenomeproject.org\/","DOI":"10.1007\/978-1-4614-7394-7"},{"key":"9689_CR107","doi-asserted-by":"publisher","unstructured":"Zhou Y, Jiang X (2012) Dissecting android malware: characterization and evolution. In: 2012 IEEE Symposium on security and privacy, pp 95\u2013109. https:\/\/doi.org\/10.1109\/SP.2012.16","DOI":"10.1109\/SP.2012.16"},{"key":"9689_CR108","doi-asserted-by":"publisher","unstructured":"Zuo C, Wu J, Guo S (2015) Automatically detecting ssl error-handling vulnerabilities in hybrid mobile web apps. In: Proceedings of the 10th ACM symposium on information, computer and communications security, ASIA CCS \u201915. ACM, New York, pp 591\u2013596. https:\/\/doi.org\/10.1145\/2714576.2714583","DOI":"10.1145\/2714576.2714583"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10664-019-09689-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-019-09689-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-019-09689-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,13]],"date-time":"2023-09-13T19:55:43Z","timestamp":1694634943000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10664-019-09689-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,2,20]]},"references-count":108,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2019,8]]}},"alternative-id":["9689"],"URL":"https:\/\/doi.org\/10.1007\/s10664-019-09689-7","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,2,20]]},"assertion":[{"value":"20 February 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}